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Abstract 

We  ask  whether  strictly  causal  components  form  well  defined  systems  when  arranged  in  feedback 
configurations.  The  standard  interpretation  for  such  configurations  induces  a  fixed-point  constraint  on 
the  function  modelling  the  component  involved.  We  define  strictly  causal  functions  formally,  and  show 
that  the  corresponding  fixed-point  problem  does  not  always  have  a  well  defined  solution.  We  examine 
the  relationship  between  these  functions  and  the  functions  that  are  strictly  contracting  with  respect  to 
a  generalized  distance  function  on  tagged  signals,  and  argue  that  these  strictly  contracting  functions 
are  actually  the  functions  that  one  ought  to  be  interested  in.  We  prove  a  constructive  fixed-point 
theorem  for  these  functions,  introduce  a  corresponding  induction  principle,  and  study  the  related 
convergence  process. 


1  Introduction 

This  work  is  part  of  a  larger  effort  aimed  at  the  construction  of  well  defined  mathematical  models  that  will 
inform  the  design  of  programming  languages  and  model-based  design  tools  for  timed  systems.  We  use  the 
term  “timed”  rather  liberally  here  to  refer  to  any  system  that  will  determinately  order  its  events  relative  to 
some  physical  or  logical  clock.  But  our  emphasis  is  on  timed  computation,  with  examples  ranging  from 
concurrent  and  distributed  real-time  software  to  hardware  design,  and  from  discrete-event  simulation  to 
continuous-time  and  hybrid  modelling,  spanning  the  entire  development  process  of  what  we  would 
nowadays  refer  to  as  cyber-physical  systems.  Our  hope  is  that  our  work  will  lend  insight  into  the  design 
and  application  of  the  many  languages  and  tools  that  have  and  will  increasingly  come  into  use  for  the 
design,  simulation,  and  analysis  of  such  systems.  Existing  languages  and  tools  to  which  this  work  applies, 
to  varying  degrees,  include  hardware  description  languages  such  as  VHDL  (see  [1])  and  SystemC  (see  [2]), 
modeling  and  simulation  tools  such  as  Simulink  and  Lab  VIEW,  network  simulation  tools  such  as  ns-2/ns-3 
and  OPNET,  and  general-purpose  simulation  formalisms  such  as  DEVS  (see  [64],  [65]),  or  even  emerging 
standards  such  as  OMG’s  SysML  (see  [3])  and  SAE’s  AADL  (see  [16]). 

Considering  the  breadth  of  our  informal  definition  for  timed  systems,  we  cannot  hope  for  a  comprehensive 
formalism  or  syntax  for  such  systems  at  a  granularity  finer  than  that  of  a  network  of  components.  We  will 
thus  ignore  any  internal  structure  or  state,  and  think  of  any  particular  component  as  an  opaque  flow 
transformer.  Formally,  we  will  model  such  components  as  functions,  and  use  a  suitably  generalized  concept 
of  signal  as  flow  (see  Definition  2.2).  This  point  of  view  is  consistent  with  the  one  presented  by  most  of  the 
languages  and  tools  mentioned  above. 

The  greatest  challenge  in  the  construction  of  such  a  model  is,  by  and  large,  the  interpretation  of  feedback. 
Feedback  is  an  extremely  useful  control  mechanism,  present  in  all  but  the  most  trivial  systems.  But  it 
makes  systems  self-referential,  with  one  signal  depending  on  another,  and  vice  versa  (see  Figure  1). 

*  This  work  was  supported  in  part  by  the  Center  for  Hybrid  and  Embedded  Software  Systems  (CHESS)  at  UC  Berkeley, 
which  receives  support  from  the  National  Science  Foundation  (NSF  awards  #0720882  (CSR-EHS:  PRET),  #0931843  (CPS: 
Large:  ActionWebs),  and  #1035672  (CPS:  Medium:  Ptides)),  the  Naval  Research  Laboratory  (NRL  #N0013-12-1-G015),  and 
the  following  companies:  Bosch,  National  Instruments,  and  Toyota. 
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Figure  1.  Block-diagram  of  a  functional  component  F  in  feedback.  The  input  signal  s  and  the  ouput  signal 
F(s)  are  but  the  same  signal;  that  is,  s  =  F(s). 


Mathematically,  this  notion  of  self-reference  manifests  itself  in  the  form  of  a  fixed-point  problem,  as 
illustrated  by  the  simple  block-diagram  of  Figure  1:  the  input  signal  s  and  the  output  signal  F(s)  are  but 
the  same  signal  transmitted  over  the  feedback  wire  of  the  system;  unless  F  has  a  fixed  point,  the  system 
has  no  model;  unless  F  has  a  unique  or  otherwise  canonically  chosen  fixed  point,  the  model  is  not  uniquely 
determined;  unless  we  can  construct  the  unique  or  otherwise  canonically  chosen  fixed  point  of  F,  we  cannot 
know  what  the  model  is.  This  imposes  constraints  on  the  functions  that  one  may  use  to  model 
components,  and  thus,  ultimately,  on  components  themselves. 

From  both  a  programming  and  a  modelling  point  of  view,  the  functions  of  primary  interest  to  the  study  of 
timed  systems  are  the  causal  functions.  Causal  functions  model  components  that  are  non-anticipative, 
meaning  that  the  output  of  the  component  does  not  depend  on  future  values  of  its  input.  But 
non-anticipative  components  can  still  react  instantaneously  to  input  stimuli,  refusing  to  assume  a  well 
defined  behavior  when  arranged  in  a  feedback  configuration  (see  Example  3.4).  For  this  reason,  causal 
functions  must  be  constrained  further. 

One  idea  is  to  impose  a  positive  lower  bound  on  the  reaction  time  of  the  component.  This  was  successfully 
carried  out,  first  by  Zeigler  in  [64],  then  by  Yates  and  Gao  in  [62]  and  [61],  then  by  Muller  and  Scholz  in 
[43] ,  and  later  again  by  one  of  us  and  colleagues  in  [28] ,  [27] ,  and  [30] .  The  same  idea  had  also  been  used  in 
the  context  of  timed  systems  by  Reed  and  Roscoe  in  [53]  and  [54]  under  the  rubric  of  realism,  but  there  are 
also  good  technical  reasons  for  it.  The  bounded  reaction-time  constraint  can  be  used  to  preclude  what  is 
known  as  the  real-time  programming  version  of  Zeno’s  paradox,  according  to  which,  infinitely  many  events 
take  place  in  a  finite  interval  of  time  (see  [4]).  This  can,  and  generally  does,  prevent  the  use  of  classical 
results  from  fixed-point  theory,  such  as  the  Banach  contraction  principle  [33],  which  has  undoubtedly  been 
the  most  successful  tool  in  the  treatment  of  recursion  and  feedback  in  timed  systems  (e.g.,  see  [53],  [54], 
[61],  [43],  [28],  [27],  [30]).  But  even  so,  the  constraint  is  excessive.  For,  even  if  not  physically  realizable, 
components  that  violate  it  are  perfectly  viable  and  extremely  common  in  modelling  and  simulation,  where 
time  is  represented  as  an  ordinary  program  variable.  And  after  the  recently  proposed  extension  of 
modelling  and  simulation  techniques  with  the  capability  to  relate  logical  and  physical  time  (see  [66]  and 
[14]),  such  components  may  even  find  their  way  into  programming  models  for  embedded  and  distributed 
real-time  systems.  The  question  is  how  much  can  one  relax  the  bounded  reaction-time  constraint. 

The  first,  natural  step  in  this  line  of  inquiry  is  to  dispose  of  any  bound,  and  simply  rule  out  what  has 
caused  trouble  in  the  first  place:  instantaneous  reaction.  What  we  are  left  with  is  the  class  of  strictly 
causal  functions.  And  the  first  question  to  ask  about  strictly  causal  functions  is  whether  every  such 
function  has  a  fixed  point.  But  in  order  to  answer  this  question,  we  need  a  formal,  mathematical  definition 
of  what  a  strictly  causal  function  is. 

In  [28],  [27],  and  [30],  strictly  causal  functions  were  defined  to  be  the  functions  that  are  strictly  contracting 
with  respect  to  the  Cantor  metric  (also  called  the  Baire  distance)  on  signals  over  non-negative  real  time. 
This  turned  out  to  be  rather  limiting,  not  only  with  respect  to  what  we  might  think  of  as  a  strictly  causal 
function,  but  also  with  respect  to  what  we  might  think  of  as  time  (see  [33]).  In  [44],  an  alternative 
definition  was  put  forward,  better  fit  to  intuition,  using  only  that  one  aspect  of  time  truly  relevant  to 
causality:  order.  In  [33],  this  definition  was  formalized  using  a  generalized  distance  function,  according  to 
which,  the  distance  between  two  signals  is  the  largest  segment  of  time  closed  under  time  precedence,  and 
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over  which  the  two  signals  agree.  This  once  more  identified  “strictly  causal”  with  “strictly  contracting” . 
But  in  all  [28],  [27],  [44],  [30],  and  [33],  the  precise  relationship  between  the  proposed  definition  and  the 
classical  notion  of  strict  causality,  as  established  within  the  physics  and  engineering  communities,  was 
never  formally  examined,  only  informally  presumed. 

From  a  classical  standpoint,  a  component  is  strictly  causal  if  and  only  if  its  output  at  any  time  depends 
only  on  past  values  of  the  input.  This  is  probably  a  folklore  definition,  but  one  that  is  universally  accepted. 
After  a  careful,  precise  formalization  of  it,  we  show  the  following: 

•  There  is  a  strictly  causal  endofunction  that  has  no  fixed  point  (see  Example  3.8). 

Therefore,  the  class  of  strictly  causal  functions  is,  in  its  entire  generality,  too  large.  In  fact,  even  the  class 
of  strictly  causal  functions  that  do  have  a  fixed  point  is  too  large.  In  particular,  we  show  the  following: 

•  There  is  a  strictly  causal  endofunction  that  has  more  than  one  fixed  point,  among  which  there  is  no 
canonical,  or  otherwise  sensible  choice  (see  Example  3.10). 

An  immediate  consequence  is  that  both  classes  are  actually  different  from  the  class  of  strictly  contracting 
functions  of  [33].  This  is  because  every  strictly  contracting  endofunction  of  [33]  has  exactly  one  fixed  point 
(see  [33,  thm.  3]). 

Stimulated  by  the  latter  fact,  we  begin  to  probe  the  exact  relationship  between  strictly  causal  functions 
and  the  strictly  contracting  functions  of  [33]  (henceforth  referred  to  simply  as  strictly  contracting 
functions).  We  prove  the  following: 

•  Every  strictly  contracting  function  is  strictly  causal  (see  Theorem  4.8). 

A  pleasing  development  would  be  that  every  strictly  causal  function  that  has  a  unique  fixed  point  be 
strictly  contracting.  This  is  too  much  to  hope  for  though,  and  we  show  the  following: 

•  There  is  a  strictly  causal  endofunction  that  has  a  unique  fixed  point,  but  is  not  strictly  contracting 
(see  Example  4.6). 

However,  we  prove  the  following: 

•  A  function  from  one  set  of  signals  to  another  is  strictly  contracting  if  and  only  if  for  every  causal 
function  from  the  latter  set  to  the  former,  the  composition  of  the  two  functions  has  a  fixed  point  (see 
Theorem  4.7). 

This  is  a  key  result.  Besides  completely  characterizing  strictly  contracting  functions  in  terms  of  the 
classical  notion  of  causality,  it  identifies  the  class  of  all  such  functions  as  the  largest  class  of  functions  that 
have  a  fixed  point  not  by  some  fortuitous  coincidence,  but  as  a  direct  consequence  of  their  causality 
properties.  The  implication,  we  believe,  is  that  the  class  of  strictly  contracting  functions  is  the  largest  class 
of  strictly  causal  functions  that  one  can  reasonably  hope  to  attain  a  uniform  fixed-point  theory  for. 

Interestingly,  and  rather  pleasingly,  in  the  case  of  computational  timed  systems,  the  situation  is  much 
simpler.  In  that  case,  components  are  expected  to  operate  not  on  all  signals,  but  only  on  discrete-event 
ones.  And  once  we  restrict  the  domains  of  the  functions  to  reflect  this,  the  difference  between  strictly 
causal  functions  and  strictly  contracting  ones  vanishes.  A  bit  more  generally,  we  prove  the  following: 

•  If  the  domain  of  every  signal  in  the  domain  of  the  function  is  well  ordered  under  the  time  precedence 
relation,  then  the  function  is  strictly  causal  if  and  only  if  it  is  strictly  contracting  (see  Corollary  4.11). 

In  other  words,  when  it  comes  to  timed  computation,  which  includes  the  case  of  all  languages  and  tools 
mentioned  in  the  beginning  of  this  introduction,  the  fixed-point  theory  of  strictly  contracting  functions  is 
exactly  the  fixed-point  theory  of  strictly  causal  functions.  Incidentally,  when  all  signals,  input  and  output, 
satisfy  the  above  condition,  even  the  definition  of  [28],  [27],  and  [30]  becomes  accurate,  albeit  for  different 
reasons. 
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Either  way,  it  is,  we  hope,  clear  that  the  fixed-point  problem  that  one  ought  to  be  interested  in  is  the  one 
pertaining  to  the  class  of  strictly  contracting  functions.  And  this  is  a  problem  that  is  not  typical  in 
computer  science.  For  despite  the  abundance  of  fixed-point  problems  in  the  field,  it  is  almost  invariably  the 
fixed-point  theory  of  ordered  sets  or  that  of  metric  spaces  that  is  applied  for  their  solution.  However, 
neither  of  those  is  generally  applicable  to  the  problem  in  hand.  The  reason  is  that  there  is  no  non-trivial 
order  relation  that  will  render  every  strictly  contracting  endofunction  order-preserving  (see  Theorem  A. 2), 
and  no  metric  that  will  render  every  such  endofunction  a  contraction  mapping  (see  Theorem  A. 4). 

To  our  knowledge,  there  are  only  two  results  in  the  existing  literature  that  are  generally  applicable  to  the 
problem  in  hand.  The  first  is  the  fixed-point  theorem  of  Priess-Crampe  and  Ribenboim  for  strictly 
contracting  functions  on  spherically  complete  generalized  ultrametric  spaces  (see  [49,  thm.  1]).  The  second 
is  an  ad  hoc  fixed-point  theorem  proved  by  Naundorf,  specific  to  the  type  of  functions  considered  here  (see 
[44,  thm.  1]).  And  although  the  two  have  been  proved  in  very  different  ways,  they  are  both  inherently 
non-constructive,  and  hence,  both  inadequate  for  our  purposes. 

Our  main  contribution  in  this  work  is  a  constructive  fixed-point  theorem  for  strictly  contracting  functions 
on  sets  of  signals.  We  use  the  term  “constructive”  in  the  stronger  sense  of  [11]  here  to  mean  that  we 
characterize  fixed  points  as  “limits  of  stationary  transfinite  iteration  sequences” .  Specifically,  for  every 
suitable  set  A'  of  signals,  and  every  strictly  contracting  function  F  on  A,  we  prove  the  following: 

•  The  unique  fixed  point  of  F  is  the  limit  of  the  transfinite  orbit  of  every  post-fixed  point  of  F  under 
the  function  Xx  :  X  .  F(x)  n  F(F(x))  (see  Theorem  5.13). 

By  “suitable”  we  mean  a  non-empty,  directed-complete  subsemilattice  of  the  complete  semilattice  of  all 
signals  under  the  signal  prefix  relation  (see  Section  2.3).  By  “limit”  of  an  orbit  we  mean  the  least  upper 
bound  or  join  of  that  orbit  in  that  subsemilattice.  And  by  “n”  we  denote  the  greatest  lower  bound  or  meet 
operation  of  that  semilattice. 

The  reader  might  of  course  ask  what  the  practical  merits  of  such  a  characterization  are.  We  consult  Cousot 
and  Cousot  for  an  answer  (see  [11,  p.  44]): 

The  advantage  of  characterizing  fixed  points  by  iterative  schemes  is  that  they  lead  to  practical 
computation  or  approximation  procedures.  Also  the  definition  of  fixed  points  as  limits  of 
stationary  iteration  sequences  allows  the  use  of  transfinite  induction  for  proving  properties  of 
these  fixed  points. 

Their  first  point  is  rather  evident  from  Lemma  5.9.2  and  Theorem  5.13  here.  And  as  regards  their  second 
point,  we  prove  the  following: 

•  The  unique  fixed  point  of  F  is  a  member  of  every  non-empty,  strictly  inductive  subset  of  X  that  is 
closed  under  the  function  Xx  :  X  .  F(x)  n  F(F(x))  (see  Theorem  5.16). 

We  believe  this  to  be  a  very  promising  induction  principle,  seemingly  stronger  a  proof  rule  than  the  ones 
afforded  by  the  fixed-point  theories  of  order-preserving  functions  and  contraction  mappings  (see  discussion 
in  Section  5.3). 

What  is  interesting  to  observe  is  that  our  characterization  is  purely  order-theoretic.  It  also  bares  a  close 
resemblance  to  the  respective  characterization  in  the  classical  order-theoretic  case  (see  [11]).  This 
resemblance  is  most  acutely  pronounced  in  the  following  corollary  characterization,  which  is  identical  in 
form  to  Tarski’s  characterization  of  greatest  fixed  points  of  order-preserving  functions  on  complete  lattices 
(see  [60,  thm.  1]): 

•  The  unique  fixed  point  of  F  is  the  join  of  all  post-fixed  points  of  F  (see  Theorem  5.14). 

What  is  there  to  account  for  this? 

As  Davey  and  Priestley  observe  in  [12,  p.  182],  “order  theory  plays  a  role  when  X  carries  an  order  and 
when  the  [fixed-point]  can  be  realized  as  the  join  of  elements  which  approximate  it”.  And  so,  our 
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characterization  is  just  another  testament  to  this  empirical  observation.  But  our  derivation  is  in  no  way  a 
reduction  to  an  order-theoretic  fixed-point  problem,  or  more  specifically,  a  fixed-point  problem  involving  an 
order-preserving  function.  In  fact,  we  show  the  following: 

•  There  is  a  suitable  (in  the  above  sense)  set  X  of  signals,  and  a  strictly  contracting  function  F  on  X 
such  that  \x  :  X  .  F( x)  n  F{F{x))  does  not  preserve  the  prefix  relation  (see  Example  5.15) 

Rather,  it  is  the  interplay  between  the  generalized  distance  function  and  the  prefix  relation  on  signals  that 
validates  our  construction,  and  accounts  for  the  above  observations.  Working  out  the  rules  that  govern  this 
interplay  (see  Section  2.4)  is  the  other  major  contribution  of  this  work.  Here,  these  rules  serve  to  determine 
the  extent  of  our  results,  and  simplify  our  proofs.  But  elsewhere,  we  prove  that  clauses  1  and  2  of 
Proposition  2.14  constitute  a  complete  axiomatization  of  the  relationship  between  the  generalized  distance 
function  and  the  prefix  relation  in  subsemilattices  of  signals. 

The  rest  of  this  document  is  organized  into  seven  sections.  In  Section  2,  we  set  up  the  background:  we 
review  the  concept  of  tagged  signal,  define  the  generalized  distance  function  and  prefix  relation  pertaining 
to  that  concept,  and  study  the  relationship  between  the  two.  In  Section  3,  we  formalize  the  notions  of 
causality  and  strict  causality,  and  through  a  series  of  examples,  demonstrate  that  these  notions  are  by 
themselves  too  weak  to  accommodate  a  uniform  fixed-point  theory  suitable  for  a  semantic  theory  of  timed 
systems.  In  Section  4,  we  introduce  contracting  and  strictly  contracting  functions,  and  examine  their 
relationship  to  the  causal  and  strictly  causal  functions  respectively,  as  defined  in  Section  3.  In  particular, 
we  provide  evidence  to  the  argument  that  strictly  contracting  functions  are  really  the  functions  that  one 
ought  to  focus  on.  The  fixed-point  theory  of  these  functions  is  developed  in  Section  5.  Starting  from  a 
more  structured  reworking  of  Naundorf’s  fixed-point  existence  argument,  we  prove  a  constructive 
fixed-point  theorem,  introduce  a  corresponding  induction  principle,  and  study  the  related  convergence 
process.  In  Section  6,  we  review  the  developed  theory,  assessing  its  practicability,  and  in  Section  7,  we 
discuss  related  work.  We  conclude  in  Section  8  with  a  few  directions  for  future  work.  Finally,  in 
Appendix  A,  we  include  proof  that  the  standard  fixed-point  theories  of  ordered  sets  and  metric  spaces  are 
not  generally  applicable  to  the  problem  in  hand. 


2  Background 

In  this  section,  we  set  the  scene  for  our  work.  Our  basic  framework  is  inspired  by  the  tagged-signal  model 
of  [28].  The  generalized  distance  function  of  Section  2.2  was  first  introduced  and  studied  in  [33],  and  the 
prefix  relation  of  Section  2.3  is  rather  standard,  but  the  analysis  of  the  relationship  between  the  two  in 
Section  2.4  is  new. 


2.1  Tagged  signals 

The  term  “signal”  is  typically  applied  to  something  that  conveys  information  via  some  form  of  variation 
(e.g.,  see  [46],  [29]).  Mathematically,  one  commonly  represents  signals  as  functions  over  one  or  more 
independent  variables.  Here,  we  are  concerned  with  signals  that  involve  a  single  independent  variable 
standing  for  some,  possibly  conceptual,  notion  of  time. 

We  postulate  a  non-empty  set  T  of  tags ,  and  an  order  relation1  A  on  T. 

We  use  T  to  represent  our  time  domain.  The  order  relation  A  is  meant  to  play  the  role  of  a  chronological 
precedence  relation,  and  therefore,  it  is  reasonable  to  require  that  A  be  a  total  order.  However,  such  a 
requirement  is  often  unnecessary.  For  the  sake  of  generality,  we  shall  assume  that  (T,  A)  is  an  arbitrary 

1  A  binary  relation  R  is  an  order  relation  if  and  only  if  R  is  reflexive,  transitive,  and  antisymmetric. 
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ordered  set.  But  for  the  sake  of  simplicity,  if  and  when  a  stronger  assumption  is  needed,  we  shall  forgo  our 
pursuit  of  generality,  and  fall  back  on  the  requirement  that  A  be  a  total  order. 

We  would  like  to  define  signals  as  functions  over  an  independent  variable  ranging  over  T.  But  being 
primarily  concerned  with  computational  systems,  we  should  expect  our  definition  to  accommodate  the 
representation  of  variations  that  may  be  undefined  for  some  instances  or  even  periods  of  time.  In  fact,  we 
think  of  such  instances  and  periods  of  time  as  part  of  the  variational  information.  Such  considerations  lead 
directly  to  the  concept  of  partial  function. 

We  postulate  a  non-empty  set  V  of  values. 

Definition  2.1.  An  event  is  an  ordered  pair  (r,v)  £  T  x  V. 

We  write  E  for  the  set  of  all  events. 

Definition  2.2.  A  signal  is  a  single-valued* 1 2  subset  of  E. 

We  write  S  for  the  set  of  all  signals. 

Notice  that  the  empty  set  is  vacuously  single- valued,  and  hence,  by  Definition  2.2,  a  signal. 

We  call  the  empty  set  the  empty  signal. 

We  adopt  common  practice  in  modern  set  theory  and  identify  a  function  with  its  graph.  A  signal  is  then  a 
function  with  domain  some  subset  of  T,  and  range  some  subset  of  V,  or  in  other  words,  a  partial  function 
from  T  to  V. 

Assume  si, S2  G  S  and  r  £  T. 

We  write  si(r)  ~  S2(t)  if  and  only  if  one  of  the  following  is  true: 

1 .  t  $  dom  si  and  r  ^  dom  S2; 

2.  t  £  dom  si,  r  £  dom  s 2,  and  si(r)  =  s2(t). 

In  other  words,  we  use  ~  to  denote  Kleene’s  equality  among  partially  defined  event  expressions. 


2.2  The  generalized  distance  function 

There  is  a  natural,  if  abstract,  notion  of  distance  between  any  two  signals,  corresponding  to  the  largest 
segment  of  time  closed  under  time  precedence,  and  over  which  the  two  signals  agree;  the  larger  the  segment, 
the  closer  the  two  signals.  Under  certain  conditions,  this  can  be  couched  in  the  language  of  metric  spaces 
(e.g.,  see  [28],  [27],  [30]).  All  one  needs  is  a  map  from  such  segments  of  time  to  non- negative  real  numbers. 
But  this  step  of  indirection  excessively  restricts  the  kind  of  ordered  sets  that  one  can  use  as  models  of  time 
(see  [33]),  and  in  fact,  can  be  avoided  as  long  as  one  is  willing  to  think  about  the  notion  of  distance  in  more 
abstract  terms,  and  use  the  language  of  generalized  ultrametric  spaces3  instead  (see  [50],  [51]). 

2  For  every  set  A  and  B,  and  every  S  C  A  X  B,  S  is  single-valued,  if  and  only  if  for  any  (o,\  ,h]).  (02 , 62)  £  S,  if  ai  =  0.2 , 
then  bi  =62- 

3  For  every  set  A,  every  pointed4 ordered  set  (P,  0),  and  every  function  d  from  A  x  A  to  P,  (A,  P,  0,  d)  is  a  generalized 

ultrametric  space  if  and  only  if  for  any  a±,  a2,  a.3  E  A  and  every  p  E  P,  the  following  are  true: 

1.  d(ai,a2)  =  0  if  and  only  if  a\  =  (12; 

2.  d(ai,  (12)  =  d(ct2,  ai); 

3.  if  d(ai,  <12)  ^  p  and  d(a2, 013)  ^  p,  then  d(ai,  as)  ^  p. 

4  An  ordered  set  is  pointed  if  and  only  if  it  has  a  least  element.  We  write  (P,  0)  for  a  pointed  ordered  set  (P,  with 

least  element  0. 
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We  write  d  for  a  function  from  S  x  S  to  ££  (T,  X)  such  that  for  every  si,  S2  £  S,5 
d(si,  s2)  =  {r  I  r  G  T  and  for  every  r'  ■<  r,  Si(r')  ~  s2(t')}. 

Proposition  2.3.  (S,J£?  (T,^),D,T,d)  zs  a  generalized  ultrametric  space. 

Proof.  See  [34,  lem.  1] .  □ 

The  following  is  immediate,  and  indeed,  equivalent: 

Proposition  2.4.  For  every  si,S2,S3  £  S,  the  following  are  true: 

1.  d(si,  S2)  =  T  if  and  only  if  si  =  S2; 

2.  d(si,s2)  =  d(s2,si); 

3.  d(si,s2)  2  d(si,s3)  nd(s3,s2). 

We  refer  to  clause  1  as  the  identity  of  indiscernibles ,  clause  2  as  symmetry ,  and  clause  3  as  the  generalized 
ultrametric  inequality. 

Proposition  2.5.  (S,  ££  (T,  X),  D,  T,  d)  is  spherically  complete7 . 

Proof.  See  [34,  lem.  2] .  □ 

Spherical  completeness  implies  Cauchy-completeness9,  but  the  converse  is  not  true  in  general  (see  [22, 
prop.  10]).  The  following  shows  that  it  is  not  true  in  the  special  case  of  generalized  ultrametric  spaces  of 
signals  either: 

Example  2.6.  Suppose  that  T  =  M,  and  R  is  the  standard  order  on  R. 

Let  X  =  {s  |  s  £  S  and  for  every  r  £  T,  s  \  {V  |  t'  <  t}  is  finite}.12 
It  is  easy  to  see  that  ( X ,  (T,  X),  D,  T,  d)  is  Cauchy-complete. 

Let  v  be  a  value  in  V. 

Let  C  =  {{s  |  s  £  X  and  d(s,  {(1  -  ^+i,v)  I  m  <  n})  D  (-00,  ^]}  |  n  £  N}.13 

The  ordered  set  (C,  C)  is  a  non-empty  chain  of  balls  in  ( X ,  (T,  ■<},  D,  T,  d),  but  p|  C  =  0.  Thus, 

(X,«5?  (T,  :<),  D,  T,  d)  is  not  spherically  complete. 

5  For  every  ordered  set  (P,  $C),  we  write  ££  (P,  for  the  set  of  all  lower  sets6  of  (P,  ^). 

6  For  every  ordered  set  (P,  $C),  and  every  L  C  P,  L  is  a  lower  set  (also  called  a  down-set  or  an  order  ideal)  of  (P,  if  and 
only  if  for  any  pi,p2  G  P,  if  pi  ^  P2  and  p2  G  P,  then  pi  G  P. 

7  A  generalized  ultrametric  space  (A,  P,  ^,0 ,  d)  is  spherically  complete  if  and  only  if  for  every  non-empty  chain  C  of  balls8 
in  (A,P,^,0,d), 

8  For  every  generalized  ultrametric  space  (A,  P,  0,  d),  and  every  B  C  A,  B  is  a  ball  in  (A,  P,  0,  d)  if  and  only  if  there  is 
c  G  A  and  p  G  P  such  that  B  =  {a  G  X  |  d(a ,  c)  ^  p}. 

9  A  generalized  ultrametric  space  (A,  P,  ^,0,d)  is  Cauchy- complete  if  and  only  if  for  every  sequence  (an  |  n  G  w)  over  A,  if 
(an  |  n  G  cj)  is  Cauchy10  in  (A,  P,  0,  d),  then  there  is  a  G  A  such  that  for  every  p  G  P  such  that  p  ^  0,  there  is  n  G  w  such 
that  for  every  n'  >  n,  d(an/ ,  a)  <  p.* 11 

10  For  every  generalized  ultrametric  space  (A,  P,  0,  d),  a  sequence  ( an  \  n  G  to)  over  A  is  Cauchy  in  (A,  P,  0,  d)  if  and 
only  if  for  every  p  G  P  such  that  p  7^  0,  there  is  n  G  w  such  that  for  every  ni,  712  >  u,  d(ani ,  an2)  <  p. 

11  We  write  uj  for  the  least  limit  ordinal. 

12  For  every  function  f  and  every  set  A,  we  write  f  \  A  for  the  restriction  of  f  to  A,  namely  the  function 
{(a,  6)  |  (a,  6)  G  /  and  aG  A}. 

13  We  write  N  for  the  set  of  all  natural  numbers. 
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The  importance  of  spherical  completeness  will  become  clear  in  Section  4.2  (see  Theorem  4.4  and 
Theorem  4.5). 

Finally,  notice  that  if  (T,  <)  is  totally  ordered,  then  (Jz?  (T,  A),  D)  is  also  totally  ordered.  This  is  really 
why  more  can  be  proved  under  the  requirement  that  ■<  be  a  total  order.  Proposition  2.7  is  a  case  in  point 
that  will  come  of  use. 

Assume  si, s2,  S3  €  S  and  L  £  Jz?  (T,  A). 

Proposition  2.7.  If  (T,  A)  is  totally  ordered,  then  */d(si,s2)  D  L  and  d(s2,S3)  D  L,  then  d(si,S3)  D  L. 
Proof.  Suppose  that  (T,  A)  is  totally  ordered. 

Then  (Jz?  (T,  <),  D)  is  totally  ordered,  and  thus,  if  d(si,  S2)  D  L  and  d(s2,  s 3)  D  L ,  then 

d(si,s2)nd(s2,s3)  D  L.  (1) 

And  since 

d(si,  s2)  A  d(si,  s2)  n  d(s2,  s3) 

and 

d(s2,  s3)  A  d(si,  s2)  n  d(s2,  s3), 
by  the  generalized  ultrametric  inequality, 

d(si,s3)  D  d(si,s2)  nd(s2,s3).  (2) 

Thus,  by  (1)  and  (2),  d(si,S3)  D  L.  □ 

The  above  stronger  variant  of  the  generalized  ultrametric  inequality  cannot  be  proved  in  general. 

Example  2.8.  Suppose  that  T  =  {0, 1},  and  A  is  the  discrete  order14  on  {0, 1}. 

Let  v  be  a  value  in  V. 

Let  Si  =  {(0, «)}. 

Let  s2  =  0. 

Let  s3  =  {(l,u)}. 

Then  d(si,  s2)  =  {1}  D  0  and  d(s2,  s3)  =  {0}  D  0,  but  d(s1;  s3)  =  0. 

2.3  The  prefix  relation 

There  is  also  a  natural  order  relation  on  signals,  namely  the  prefix  relation  on  signals. 

We  write  E  for  a  binary  relation  on  S  such  that  for  every  si,  s2  £  S, 

Si  E  s2  <*=>■  for  every  r,  t'  £  T,  if  r  e  dom  si  and  t'  A  r,  then  Si(r')  ~  S2(t'). 

Assume  si,  s2  £  S. 

We  say  that  si  is  a  prefix  of  s2  if  and  only  if  si  Cs2. 

Notice  that  for  every  s  £  S,  0  E  s;  that  is,  the  empty  signal  is  a  prefix  of  every  signal. 

14  For  every  set  A,  the  discrete  order  on  A  is  the  smallest  order  relation  on  A,  namely  the  unique  order  relation  on  A  with 
respect  to  which  any  two  distinct  members  of  A  are  incomparable. 


Proposition  2.9.  (S,  C)  is  an  ordered  set. 
Proof.  Easy. 


□ 


Proposition  2.10.  For  every  CCS  such  that  C  is  consistent 15  in  (S,  C),  (J  C  is  the  least  upper  bound  of 
C  in  (S,  C). 

Proof.  Assume  CCS  such  that  C  is  consistent  in  (S,  C). 

We  first  prove  that  (J  C  €  S. 

Suppose,  toward  contradiction,  that  (J  C  ^  S.  Then  there  are  si,  S2  £  C  and  r  such  that  r  £  dom  Si  and 
r  £  dom  S2,  but  si(t)  7^  S2(t).  Thus,  {si,  S2}  cannot  have  an  upper  bound  in  (S,  C),  contrary  to  the 
hypothesis  that  C  is  consistent  in  (S,C). 

Therefore,  |J  C  £  S. 

Assume  s  £  C. 

Suppose,  toward  contradiction,  that  s  %  [J  C.  Then  there  are  r,  r'  £  T  such  that  r  £  dom  s  and  t'  A  t,  but 
s(r')  qf±  (IJ  C)(t').  And  since  s  C  (J  C,  t'  £  dom  s,  and  there  is  s'  £  C  such  that  t'  £  dom  s'.  However, 

{s,  s'}  cannot  have  an  upper  bound  in  (S,  C),  contrary  to  the  hypothesis  that  C  is  consistent  in  (S,  C). 

Therefore,  s  C  (J  C. 

Assume  u  £  S  such  that  u  is  an  upper  bound  of  C  in  (S,  C). 

Suppose,  toward  contradiction,  that  IJ  C  %  u.  Then  there  are  r,  r'  £  T  such  that  r  £  dom  J  C  and  r'  A  r, 
but  (J  C)(t')  qk  u(t').  Thus,  there  is  s  £  C  such  that  r  £  dom  s,  but  s(t')  qk  u(t'),  and  hence,  s  %  u, 
contrary  to  the  assumption  that  u  is  an  upper  bound  of  C  in  (S,  C). 

Therefore,  J  C  C  u. 

Thus,  by  generalization,  J  C  is  the  least  upper  bound  of  C  in  (S,  C).  □ 

Assume  CCS  such  that  C  is  consistent  in  (S,  C). 

We  write  J  C  for  the  least  upper  bound  of  C  in  (S,  C). 

The  following  is  immediate: 

Proposition  2.11.  (S,C)  is  a  complete  semilattice 16. 

Assume  non-empty  I  CS. 

We  write  |~]  X  for  the  greatest  lower  bound  of  A'  in  (S,  C). 

The  next  proposition  provides  an  alternative,  and  arguably,  more  intuitive  definition  of  the  prefix  relation 
on  signals,  that  will  be  useful  in  relating  the  latter  with  the  generalized  distance  function  of  Section  2.2. 

Proposition  2.12.  si  C  S2  if  and  only  if  there  is  L  £  22?  (T,  A)  such  that  s\  =  S2  f  L. 

15  For  every  ordered  set  ( P ,  ^) ,  and  every  C  C  P,  C  is  consistent  in  (P,  y }  if  and  only  if  C  ^  0,  and  every  finite  subset  of  C 
has  an  upper  bound  in  (P,  y ) . 

16  An  ordered  set  (P,  is  a  complete  semilattice  if  and  only  if  every  non-empty  subset  of  P  has  a  greatest  lower  bound  in 

(P,  y ) ,  and  every  subset  of  P  that  is  directed1'  in  (P, . )  has  a  least  upper  bound  in  (P,  p) . 

17  For  every  ordered  set  (P,  y) ,  and  every  D  C  D  is  directed  in  (P, . }  if  and  only  if  and  every  finite  subset  of  D 

has  an  upper  bound  in  ( D ,  ^). 
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Proof.  Suppose  that  si  C  s2. 

Suppose,  toward  contradiction,  that 

si  7^  s2  f  d(si,  s2). 

Then  there  is  r  such  that 

si(t)  (s2  \  d(si,s2))(r). 

Suppose  that  r  £  dom  si.  Then,  since  Si  C  s2,  si(r)  =  s2(r),  and  thus,  r  ^  d(si,  s2).  Thus,  there  is  t'  <  t 
such  that  si(r')  ^  s2(r'),  contrary  to  the  hypothesis  that  si  C  s2. 

Otherwise,  r  ^  dom  sj..  Then  r  €  dom  s2  f  d(si,  s2).  Thus,  r  £  d(si,  s2),  but  Si(r)  ~  s2(r),  obtaining  a 
contradiction. 

Therefore, 

si  =  s2  \  d(si,  s2), 

and  thus,  there  is  Leif  (T,  A),  namely  d(si,  s2),  such  that  Si  =  s2  f  L. 

Conversely,  suppose  that  there  is  L  £  Jz?  (T,  such  that  Si  =  s2  \  L.  Then  for  every  r,  t'  £  T,  if 
r  £  dom  si  and  r'  A  r,  then,  since  L  is  a  lower  set  of  (T,  A),  t'  £  L ,  and  thus,  si(r')  ~  s2(r').  Thus, 

Si  C  s2.  □ 

2.4  The  relationship  between  the  generalized  distance  function  and  the  prefix 
relation 

Looking  more  closely  at  the  proof  of  Proposition  2.12,  we  see  that  there  is  actually  a  canonical  choice  for 
the  witness  L ,  namely  d(si,  s2).  The  next  theorem  is  a  powerful  generalization  of  this  observation. 

Theorem  2.13.  For  every  non-empty  ICS  and  every  s  £  X, 

n*  =  s  r  n  {4(si,  s2)  i  si,  s2  £  x}. 

Proof.  Assume  non-empty  ACS. 

Assume  s  £  X. 

Assume  s'  £  X. 

Suppose,  toward  contradiction,  that 
s  f  d^s7)  ^  s'  f  d(s,s/). 

Then  there  is  r  such  that 

(s  \  d (s,s'))(t)  (s'  \  d(s,  s/))(r). 

Without  loss  of  generality,  assume  that  r  £  dom(s  f  d(s,  s')).  Then  r  £  d(s,  s'),  and  thus,  s(r)  ~  s'(t). 
Hence, 

(s  \  d(s,  s,))(r )  ~  (s'  \  d(s,  s'))(r), 
obtaining  a  contradiction. 
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Therefore, 

s  1"  d(s,  s')  =  s'  f  d(s,  s'). 

Since  s,  s'  £  A, 

d(s,  s')  D  f|{d(si,s2)  |  s1,s2  £  A}, 
and  thus, 

s  f  f|  {d(si,  s2)  |  si,  s2  £  X}  =  (s  f  d (s,  s'))  \  f|  {d(si,  s2)  |  si,  s2  £  Xj 

=  (s'  t  d(s,  s'))  \  f|  {d(si,  s2)  I  Si,  s2  £  X} 

=  s'  r  pi  {d(si,  s2)  |  si,  s2  £  A"}. 

Hence,  by  Proposition  2.12, 

s  \  fl  {d(si,  s2)  |  si,  s2  £  X}  C  s'. 

Thus,  by  generalization,  s  (  f  {d(si,  s2)  |  si,  s2  £  X}  is  a  lower  bound  of  A'  in  (S,  C). 

Assume  l  £  S  such  that  l  is  a  lower  bound  of  X  in  (S,  C). 

Since  l  is  a  lower  bound  of  X  in  (S,  C),(Cs. 

Suppose,  toward  contradiction,  that 
1%  s  \  fl  {d(si,  s2)  I  Si,  s2  £  X}. 

Then  there  are  r,  r'  £  T  such  that  r  £  dom  l  and  t1  A  r,  but 
1(t')  (s  m{d(*i,s2)  |  si,s2  £  X})(t’). 

If  t'  £  dom  l,  then  t'  £  dom(s  f  p|  {d(si,  s2)  |  Si,  s2  £  X}).  Thus,  t'  £  dom  s,  and  hence,  l(r')  s(t'). 

Thus,  l  %  s,  contrary  to  the  assumption  that  l  is  a  lower  bound  of  X  in  (S,  C). 

Otherwise,  r'  £  dom  l,  and  since  l  C  s,  t'  £  dom  s  and  1(t')  =  s(t'). 

If  t'  £  p|  {d(si,  s2)  |  si,  s2  £  A},  then 

(s  \  f|  {d(si,  s2)  |  si,  s2  £  A})(t')  ~  s(r') 

=  Kr'), 

obtaining  a  contradiction. 

Otherwise,  t'  £  f  {d(si,  s2)  |  si,  s2  £  A},  and  thus,  there  are  Si,  s2  £  A  such  that  t'  qL  d(si,  s2).  Then 
there  is  t"  A  r'  such  that  Si(r")  ^  s2(r"),  and  thus,  1(t")  ^  Si(r")  or  1(t")  qk  s2(t").  Without  loss  of 
generality,  assume  that  1(t")  qk  si(t”).  Then,  since  r  £  dom  l  and  t"  A  r,  l  %  si,  contrary  to  the 
assumption  that  l  is  a  lower  bound  of  A  in  (S,  C). 

Therefore, 

l  E  s  T  f  {d(si,  s2)  |  si,  s2  £  A}. 

Thus,  by  generalization,  s  f  f  {d(si,  s2)  |  si,  s2  £  A}  is  the  greatest  lower  bound  of  X  in  (S,  C).  □ 

Theorem  2.13  is  a  fine  portrait  of  the  relationship  between  d  and  C.  The  only  problem  is  that  it  is  too 
concrete.  Being  expressed  in  the  language  of  set  theory,  it  is  closely  tied  to  the  low-level  representation  of 
signals.  In  practice,  one  would  rather  work  at  a  higher  level  of  abstraction,  and  ignore  the  low-level 
representation  details.  The  next  proposition  aims  at  distilling  the  essence  of  Theorem  2.13  (at  least  with 
respect  to  the  needs  of  this  work)  into  a  couple  of  simple  properties  expressed  in  a  language  that  only 
references  d  and  C.18 

18  Notice  that  fl  is  definable  in  (S,  C),  and  conversely,  C  is  definable  in  (S,  n). 
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Proposition  2.14.  For  every  Si,s2,s3  £  S,  the  following  are  true: 

1.  if  d(si,  s2)  2  d(si,  S3),  then  si  n  S3  C  Si  n  s2; 

2.  d(si  n  s2,  Si  n  s3)  2  d(s2,  s3). 

Proof.  Assume  si,S2,S3  £  S. 

Suppose  that 

d(si,s2)  2  d(si,s3).  (3) 

Then,  by  Theorem  2.13  and  (3), 
si  n  s3  =  si  f  d(si,s3) 


=  (si  r  d(si,  s2))  \  d(si,s3) 
=  (si  n  s2)  f  d(si,  s3). 


and  thus,  by  Proposition  2.12, 
si  n  s3  E  si  n  s2. 

Thus,  1  is  true. 

Suppose,  toward  contradiction,  that 
d(si  n  s2,  si  n  s3)  2  d(s2,  s3). 

Then  there  is  r  such  that  r  G  d(s2,  S3),  but  r  ^  d(si  fl  s2,  Si  fl  S3).  Thus,  there  is  t'  Ft  such  that 


(si  n  s2)(t')  2  (si  n  s3)(t')- 


(4) 


Without  loss  of  generality,  assume  that 
t'  £  dom(si  fl  s2). 


(5) 


Then,  by  Theorem  2.13, 
t'  G  d(si,s2). 


(6) 


And  since  r  £  d(s2,  S3)  and  r'  A  r, 
t'  e  d(s2,  s3). 


(7) 


By  (6),  (7),  and  the  generalized  ultrametric  inequality, 


t’  G  d(si,s3) 


(8) 


And  by  Theorem  2.13,  (5),  and  (8), 

(si  n  s2)(t')  =  (si  t  d(si,  s2))(t') 


= 

=  (si  r  d(si,s3))(T/) 
=  (si  n  s3)(r'). 


in  contradiction  to  (4). 
Therefore, 


d(si  n  s2,  Si  n  S3)  2  d(s2,  S3). 
Thus,  2  is  true. 


□ 
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Looking  more  closely  at  the  proof  of  Proposition  2.14.1,  we  see  that  Proposition  2.14.1  is  actually  true  in 
every  semilattice19  of  signals.  This  is  not  the  case  for  Proposition  2.14.2. 

Example  2.15.  Suppose  that  T  =  {0, 1,  2},  and  ^  is  the  standard  order  on  {0, 1,  2}. 

Let  v  be  a  value  in  V. 

Let  si  =  {(0,t;),  (1,7;)}. 

Let  s2  =  |(0,t;),  (2,7;)}. 

Let  s3  =  0. 

Clearly,  ({si,  s2,  s3},  C)  is  a  semilattice.  However, 

d(si  C|Sl ,s2,S3}  Si,  Si  ^  ^{si ,S2 ,53}  ^2)  d(si,  s3) 

=  0 

=  d(si,s2). 

However,  for  every  semilattice  of  signals,  if  that  semilattice  is  a  subsemilattice20  of  (S,  C),  then  both 
clauses  of  Proposition  2.14  are  true  in  it.  Rather  pleasingly,  the  converse  is  also  true. 

Proposition  2.16.  If  („Y,  C)  is  a  semilattice,  then  the  following  are  equivalent: 

1.  the  following  are  true: 

(a)  if  d(s1;  s2)  2  d(si,s3),  then  Si  Hx  s3  C  Si  Hx  s2; 

(b)  d(si  rix  s2,  si  nx  s3)  2  d(s2,  S3); 

2.  {X,  C)  is  a  sub  semilattice  of  { S,C). 

Proof.  Suppose  that  ( X ,  C)  is  a  semilattice. 

Suppose  that  1  is  true. 

Suppose,  toward  contradiction,  that  2  is  not  true.  Then  there  are  si,  s2  £  X  such  that 

si  nx  s2  c  si  n  s2.  (9) 

However,  by  lb, 

d(si,  Si  rix  s2)  =  d(si  nx  Si,  Si  nx  S2) 

2  d(si,s2), 

and  thus,  by  Proposition  2.14.1, 

si  n  s2  c  si  n  (si  nx  s2) 

=  si  nx  s2, 

in  contradiction  to  (9). 

19  An  ordered  set  (P, s  }  is  a  semilattice  if  and  only  if  every  non-empty  finite  subset  of  P  has  a  greatest  lower  bound  in 

20  For  every  semilattice  (P,  Si),  and  every  SCP,  (S,  y )  is  a  subsemilattice  of  (P,  y  ;  if  and  only  if  every  non-empty  finite 
subset  of  S  has  a  greatest  lower  bound  in  ( S ,  £) ,  and  that  greatest  lower  bound  is  the  greatest  lower  bound  of  that  subset  in 
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Therefore,  2  is  true. 

Conversely,  if  2  is  true,  then  for  every  si,  s2  £  X, 


si  n.v  s2  =  si  n  s2, 

and  thus,  by  Proposition  2.14,  1  is  true.  □ 

Elsewhere,  we  prove  that,  under  the  hypothesis  of  (T,  <)  being  totally  ordered,  clauses  1  and  2  of 
Proposition  2.14  constitute  a  complete  axiomatization  of  the  relationship  between  the  generalized  distance 
function  and  the  prefix  relation  in  subsemilattices  of  signals.  It  is  then  natural  to  wonder  how  these 
“axioms”  came  about.  The  simple  answer  is  that  they  presented  themselves  while  first  proving  our  main 
fixed-point  theorem;  they  emerged  as  a  minimal  set  of  properties  sufficient  to  eliminate  any  reference  to 
individual  tags  and  values. 

The  entire  fixed-point  theory  of  Section  5  is  essentially  built  on  Proposition  2.14.  Its  use  has  allowed  for  a 
much  simpler  theory,  abstract  enough  to  potentially  interest  other  branches  of  computer  science  involving 
similar  structures,  such  as,  for  example,  programming  logic  (e.g.,  see  [52],  [21]). 

Finally,  it  is  instructive  to  contradistinguish  between  the  two  concepts  of  completeness  associated  with  the 
generalized  distance  function  and  the  prefix  relation  respectively,  namely  the  concept  of  spherical 
completeness  and  that  of  directed-completeness21. 

Example  2.17.  Suppose  that  T  =  Q,  and  ^  is  the  standard  order  on  Q.22 
Suppose  that  V  is  a  singleton  set. 

Let  D  =  {{|}  x  V,  {|,  §}  x  V,  {|,  §,  f}  x  V,...}. 

LetX  =  I5u{({i,§,f,...}U{l})xV,({i,§,f,...}U{2})x  V}. 

It  is  not  hard  to  verify  that  (A',  ££  (T,  ^),  D,T,d)  is  spherically  complete.  However,  (A,  C)  is  not 
directed-complete:  D  is  directed  in  (A',  C),  but  has  no  least  upper  bound  in  (X,  C). 

Example  2.18.  Suppose  that  T  =  N,  and  ^  is  the  standard  order  on  N. 

Suppose  that  V  is  a  singleton  set. 

Let  X  =  {0}  U  {(N  -  {1})  x  V,  (N  -  {2})  x  V,  (N  -  {3})  x  V, . . .}. 

For  every  Si,s2  S  X,  Si  C  s2  if  and  only  if  si  =  0  or  s  1  =  s2.  Thus,  trivially,  (X,  C)  is  directed-complete. 
Let  C  =  {{s  |  s  £  X  and  d(s,  (N  —  {n  +  1})  x  V)3  {m  \  m  <  n}}  \  n  €  N}. 

The  ordered  set  (C,  C)  is  non-empty  a  chain  of  balls  in  (X,  ££  (T,  ^),  D,  T,  d),  but  f)  <7  =  0.  Thus, 

(X,  j£f  (T,  ^),  D,  T,  d)  is  not  spherically  complete. 

Notice  that  the  ordered  set  of  Example  2.18  is  actually  a  semilattice.  We  defer  the  case  of  a  subsemilattice 
to  Section  5.1  (see  Corollary  5.6  and  Example  5.8). 

21  An  ordered  set  (P,  -y)  is  directed-complete  if  and  only  if  every  subset  of  P  that  is  directed  in  (P,  has  a  least  upper 
bound  in  (P,  ^). 

22  We  write  Q  for  the  set  of  all  rational  numbers. 
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3  Causal  and  strictly  causal  functions 


In  this  section,  we  formalize  the  folklore,  but  well  established,  notions  of  causality  and  strict  causality,  and 
through  a  series  of  examples,  demonstrate  that  these  notions  are  by  themselves  too  weak  to  accommodate 
a  uniform  fixed-point  theory  suitable  for  a  semantic  theory  of  timed  systems. 


3.1  Causal  functions 


Causality  is  a  concept  of  fundamental  importance  in  the  study  of  timed  systems.  Informally,  it  represents 
the  constraint  that,  at  any  time  instance,  the  output  events  of  a  component  do  not  depend  on  its  future 
input  events.  This  is  only  natural  for  components  that  model  or  simulate  physical  processes,  or  realize 
online  algorithms;  an  effect  cannot  precede  its  cause. 

Assume  a  partial  function  F  on  S. 

We  say  that  F  is  causal  if  and  only  if  there  is  a  partial  function  /  such  that  for  any  s  £  dom  F  and  every 
re  T, 

F(s)(t)  ~  f(s  \  {t  |  t'  A  t},t). 

Notice  that  since  s  is,  in  general,  a  partial  function,  s(t)  need  not  be  defined,  and  thus,  r  cannot,  in 
general,  be  inferred  from  s  \  { t'  \  t'  A  r},  and  must  be  provided  as  a  separate  argument. 

Example  3.1.  Suppose  that  T  =  N,  and  A  is  the  standard  order  on  N. 

Suppose  that  V  =  K.23 

Let  F  be  a  function  on  S  such  that  for  every  s  £  S  and  every  r  £  T, 

F  MM  =  £  {s(n)  |  0  £  n  A  r  and  n  £  dom  s}. 


Clearly,  F  is  causal. 

The  function  of  Example  3.1  models  a  component  that,  at  each  time  instance,  produces  an  event  whose 
value  is  the  running  total  of  the  values  of  all  input  events  occurring  before  or  at  that  time  instance.  The 
function  of  our  next  example  models  a  simple  sampling  process,  and  substantiates  our  claim  that  r  must 
be  provided  as  a  separate  argument. 


Example  3.2.  Suppose  that  T  =  K,  and  A  is  the  standard  order  on  R. 
Let  p  be  a  positive  real  number. 

Let  F  be  a  function  on  S  such  that  for  every  s£S  and  every  r  £  T, 


F(s)(r) 


s(t)  if  there  is  i  £  Z  such  that  r  =  p  ■  t;24 

undefined  otherwise. 


Clearly,  F  is  causal. 

Of  course,  unless  T  is  a  singleton,  not  every  function  on  S  is  causal.  The  function  of  our  next  example 
models  a  constant  look-ahead  process,  and  is  a  simple  instance  of  a  function  on  S  that  is  not  causal. 

23  We  write  R  for  the  set  of  all  real  numbers. 

24  We  write  Z  for  the  set  of  all  integers. 
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Example  3.3.  Suppose  that  R,  and  R  is  the  standard  order  on  R. 

Let  F  be  a  function  on  S  such  that  for  every  s  £  S  and  every  r  €  T, 

F(s)(t)  ~  s(t  +  1). 

Clearly,  F  is  not  causal. 

Now,  as  explained  in  Section  1,  due  to  its  relevance  to  the  interpretation  of  feedback,  of  special  interest  is 
whether  any  particular  partial  function  F  on  S  has  a  fixed  point,  that  is,  whether  there  is  s  G  S  such  that 

s  =  F(s) 

(see  Figure  1),  and  whether  that  fixed  point  is  unique.  The  function  of  Example  3.1  has  exactly  one  fixed 
point,  namely  N  x  {0},  whereas  that  of  Example  3.2  has  uncountably  many  fixed  points,  namely  every 
seS  such  that 

dom  s  C  {r  |  there  is  i  £  Z  such  that  t  =  p  ■  i}. 

Even  the  non-causal  function  of  Example  3.3  has  uncountably  many  fixed  points,  namely  every  s  €  S  such 
that  for  every  r  £  R, 

s(t)  ~  s(r  +  1). 

However,  it  is  easy  to  construct  a  causal  function  that  does  not  have  a  fixed  point. 

Example  3.4.  Let  r  be  a  tag  in  T. 

Let  v  be  a  value  in  V. 

Let  F  be  a  function  on 

F(a)  =  {(<-» 

It  is  easy  to  verify  that 
F(0)  =  {(t,u)}. 

The  function  of  Example  3.4  models  a  component  whose  behaviour  at  r  resembles  a  logical  inverter, 
turning  presence  of  event  into  absence  of  event,  and  vice  versa. 

Finally,  we  note  that  causal  functions  are  closed  under  function  composition. 


S  such  that  for  every  s  £  S, 

if  t  e  dom  s; 
otherwise. 

F  is  causal.  However,  F  has  no  fixed  point;  for  F({(t,  v)})  =  0,  whereas 


3.2  Strictly  causal  functions 

Strict  causality  is  causality  bar  instantaneous  reaction.  Informally,  it  represents  the  constraint  that,  at  any 
time  instance,  the  output  events  of  a  component  do  not  depend  on  its  present  or  future  input  events.  This 
operational  definition  has  its  origins  in  natural  philosophy,  and  is  of  course  inspired  by  physical  reality: 
every  physical  system  is  a  strictly  causal  system.25 

25  In  modern  physics,  this  would  actually  depend  on  the  choice  of  interpretation  of  quantum  mechanics,  especially  with 
regard  to  paradoxes  such  as  Bell’s  theorem  (e.g.,  see  [40])  and  Wheeler’s  delayed  choice  (e.g.,  see  [23]).  Steering  clear  of  the 
far-from-settled  debate  here,  we  believe  that,  regardless  of  personal  stand,  the  reader  will  acknowledge  the  overwhelming 
plethora  of  physical  systems  that  fall  under  this  casual  description. 
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We  say  that  F  is  strictly  causal  if  and  only  if  there  is  a  partial  function  /  such  that  for  any  s  £  dom  F  and 
every  r  £  T, 

F(s)(t)  ~  f(s  \  {/  |  t'  -<  r},r). 

The  following  is  immediate: 

Proposition  3.5.  If  F  is  strictly  causal,  then  F  is  causal. 

Of  course,  the  converse  is  false.  For  example,  the  sampling  function  of  Example  3.2  is  causal  but  not 
strictly  causal. 

Example  3.6.  Suppose  that  T  =  M,  and  A  is  the  standard  order  on  R. 

Let  F  be  a  function  on  S  such  that  for  every  s  £  S  and  every  r  £  T, 

F(s){t)  ~  s(t  —  1). 


Clearly,  F  is  stricty  causal. 


The  function  of  Example  3.6  models  a  simple  constant-delay  component.  It  is  in  fact  a  “delta  causal” 
function,  as  defined  in  [28]  and  [27],  and  it  is  not  hard  to  see  that  every  such  function  is  strictly  causal  (as  is 
every  “Z\-causal”  function,  as  defined  in  [62]  and  [61]).  The  function  of  our  next  example  models  a  variable 
reaction-time  component,  and  is  a  strictly  causal  function  that  is  not  “delta  causal”  (nor  “Z\-causal” ) . 


Example  3.7.  Suppose  that  T  =  [0,  oo),  and  A  is  the  standard  order  on  [0,  oo).26 
Suppose  that  V  =  (0,oo).27 

Let  F  be  a  function  on  S  such  that  for  every  s  £  S  and  any  r  £  T, 


F(s)(t) 


1  if  there  is  t'  £  dom  s  such  that  r  =  t'  +  s(r'); 

undefined  otherwise. 


Clearly,  F  is  strictly  causal. 

Now,  the  function  of  Example  3.6  has  the  same  fixed  points  as  that  of  Example  3.3,  whereas  that  of 
Example  3.7  has  exactly  one  fixed  point,  namely  the  empty  signal.  And  having  ruled  out  instantaneous 
reaction,  the  reason  behind  the  lack  of  fixed  point  in  Example  3.4,  one  might  expect  that  every  strictly 
causal  function  has  a  fixed  point.  But  this  is  not  the  case. 


Example  3.8.  Suppose  that  T  =  Z,  and  A  is  the  standard  order  on  Z. 
Suppose  that  V  =  N. 

Let  F  be  a  function  on  S  such  that  for  every  s  £  S  and  every  r  £  T, 


F(s)(t) 


s(t  —  1)  T  1  if  r  —  1  £  dom  s; 
0  otherwise. 


Clearly,  F  is  strictly  causal.  However,  F  does  not  have  a  fixed  point;  any  fixed  point  of  F  would  be  an 
order-embedding  from  the  integers  into  the  natural  numbers,  which  is  of  course  impossible. 

26  We  write  [0,  oo)  for  the  set  of  all  non-negative  real  numbers. 

27  We  write  (0,  oo)  for  the  set  of  all  positive  real  numbers. 
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Example  3.8  alone  is  enough  to  suggest  that  the  classical  notion  of  strictly  causality  is  by  itself  too  general 
to  support  a  useful  theory  of  timed  systems.  But  lack  of  fixed  point  is  not  the  only  source  of  concern. 


Example  3.9.  Suppose  that  T  =  (0,  oo),  and  A  is  the  standard  order  on  (0,  oo). 
Suppose  that  V  =  M. 

Let  a  be  a  real  number  greater  than  1. 

Let  v  be  a  value  in  V. 

Let  F  be  a  function  on  S  such  that  for  every  s  £  S  and  every  r  £  T, 


s(r/a)  if  r/a  £  dom  s; 
undefined  otherwise. 


Clearly,  F  is  strictly  causal. 

Let  b  and  c  be  two  distinct  positive  real  numbers. 

Let  Sb  =  { (b  ■  a1 ,  v)  \  i  £  Z} . 

Let  sc  =  {(c  ■  al,v)  \  i  £  Z}. 

Then  Sb  and  sc  are  two  distinct  fixed  points  of  F. 

Imagine  arranging  a  component  that  realizes  the  function  Example  3.9  in  a  feedback  configuration,  as  in 
the  simple  block-diagram  of  Figure  1.  How  ought  it  to  behave?  To  tell  what  the  output  of  the  component 
ought  to  be  at  any  particular  time  instance,  we  need  to  look  at  what  it  was  at  some  earlier  time  instance. 
Iterating  this  argument,  we  find  ourselves  entangled  in  an  infinite  descending  causal  chain,  where  nothing 
can  be  traced  back  to  anything,  an  infinite  regress.  At  the  same  time,  we  have  no  reason  to  reject  any 
particular  option,  in  hope  that  we  might  determine  the  behavior  by  some  law  of  exclusion.  All  in  all,  there 
can  be  no  ground  for  the  output  of  the  component. 

There  is  an  interesting  analogy  put  forward  by  Dummett  in  [13]  to  explain  Thomas  Aquinas’  proof  of  the 
existence  of  God  as  First  Cause,  which  we  might  use  to  shed  some  light  on  the  situation.  An  infinite 
descending  causal  chain  is  much  like  an  infinite  proof,  or  to  be  more  precise,  a  proof  with  some  infinite 
deduction  branch.  Here  we  think  of  a  deductive  structure  in  the  form  of  a  rooted  tree,  each  node  standing 
for  a  statement  derived  by  its  children  according  to  some  inference  rule.  There  is  no  reason  whatever  to 
accept  any  of  the  statements  along  the  infinite  branch  as  true,  and  hence,  no  reason  to  accept  the 
conclusion  of  the  proof  as  true. 

The  skeptical  reader  might  well  argue  that  this  is  but  an  ostensible  issue,  and  that,  much  in  the  spirit  of 
Kahn’s  principle  for  networks  of  asynchronous  processes  (see  [24]),  the  component  will  simply  settle  at  the 
empty  signal;  if  there  is  no  reason  to  output  something,  it  will  output  nothing.  This,  however,  would  entail 
a  bias  toward  absence  of  event,  a  view  that  components  rather  remain  idle  if  they  can.  And  the  soundness 
of  such  a  view  would  ultimately  rest  on  the  operational  semantics  of  our  systems,  about  which  we  remain 
agnostic.  For  example,  such  a  view  would  be  consistent  with  the  approach  to  absence  of  event  taken  in  the 
semantics  of  statecharts  presented  in  [48] ,  but  inconsistent  with  that  taken  in  the  constructive  semantics  of 
pure  Esterel  (see  [7]).  All  the  same,  our  next  example  seems  to  leave  little  room  for  such  skepticism. 

Example  3.10.  Suppose  that  T  =  Z,  and  A  is  the  standard  order  on  Z. 

Let  v  be  a  value  in  V. 
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Let  F  be  a  function  on  S  such  that  for  every  s£S  and  every  r  £  T, 


F(s)(t) 


undefined  if  r  —  1  £  dom  s; 
v  otherwise. 


Clearly,  F  is  strictly  causal. 

Let  sotjd  =  {  (t,  v)  \  t  is  an  odd  integer} . 

Let  Seven  =  {  (r,  v)  \  t  is  an  even  integer} . 

Then  s0dd  and  seven  are  two  distinct  fixed  points  of  F. 

Unlike  Example  3.9,  there  are  only  two  fixed  points  here,  sQdd  and  seven-  The  corresponding  feedback 
system  is  just  as  indeterminate  though,  due  once  more  to  the  occurrence  of  an  infinite  descending  causal 
chain,  and  the  perfect  symmetry  among  presence  and  absence  of  event  seems  detrimental  to  any  attempt  to 
ground  any  preference  to  either  of  s0dd  and  seVen- 

Finally,  we  note  that  strictly  causal  functions  are  closed  under  function  composition  with  causal  functions. 


4  Contracting  and  strictly  contracting  functions 

In  view  of  the  examples  of  the  previous  section,  the  classical  notion  of  strictly  causality  is  by  itself  too 
general  to  support  a  useful  theory  of  timed  systems.  Indeed,  Example  3.8  alone  should  be  enough  to 
convince  one  of  the  absurdity  of  the  definition  of  strict  causality  at  that  level  of  generality.  Here,  we 
compare  causal  and  strictly  causal  functions  to  the  functions  that  are  contracting  and  strictly  contracting 
with  respect  to  the  generalized  distance  function,  and  argue  that  strictly  contracting  functions  are  actually 
the  functions  that  one  ought  to  be  interested  in. 


4.1  Contracting  functions 

There  is  another,  intuitively  equivalent  way  to  articulate  the  property  of  causality:  a  component  is  causal 
just  as  long  as  any  two  possible  output  signals  differ  no  earlier  than  the  input  signals  that  produced  them 
(see  [27,  p.  36],  [8,  p.  11],  and  [29,  p.383]).  And  this  can  be  very  elegantly  expressed  using  the  generalized 
distance  function  of  Section  2.2. 

We  say  that  F  is  contracting  if  and  only  if  for  any  S\,  s2  £  dom  F, 
d(F(s1),F(s2))  2  d(si,s2). 

In  other  words,  a  function  is  contracting  just  as  long  as  the  generalized  distance  between  any  two  signals  in 
the  range  of  the  function  is  smaller  than  or  equal  to  that  between  the  signals  in  the  domain  of  the  function 
that  map  to  them.  Notice  that,  because  A  is  not  necessarily  a  total  order,  this  is  different,  in  general,  from 
the  generalized  distance  between  any  two  signals  in  the  domain  of  the  function  being  no  bigger  than  that 
between  the  signals  in  the  range  of  the  function  that  those  map  to,  which  is  why  we  have  opted  for  the 
term  “contracting”  over  the  term  “non-expanding” . 

In  [33,  def.  5],  causal  functions  were  defined  to  be  the  contracting  functions.  Here,  we  prove  that  indeed 
they  are. 

Theorem  4.1.  F  is  causal  if  and  only  if  F  is  contracting. 
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Proof.  Suppose  that  F  is  causal. 

Then  there  is  a  partial  function  /  such  that  for  any  s  £  dom  F  and  every  r  £  T, 

F(s){t)  ~  f(s  \  {/  |  t'  A  r},r). 

Assume  si,  s2  £  dom  F. 

Suppose,  toward  contradiction,  that 
d(F(si),F(s2))  2  d(si,s2). 

Then  there  is  r  such  that  r  £  d(s1;  s2),  but  r  fL  d(F(si),  F(s2)).  Thus,  there  is  r7  A  r  such  that 
F(si)(t7)  2  F(s2)(t7).  But  since  t'  2  t,  t'  £  d(si,s2),  and  thus, 

si  \{t"  \t”  Pt'}  =  s2  Pt'}. 

Hence, 

F(Sl)(r')  ^  f(Sl  \{t"\t"  Pr'}y) 

■^f{s2\{T"\T"<T'},T') 

-  F{s2){t')1 

obtaining  a  contradiction. 

Therefore, 

d(F(si),  F(s2))  2  d(si,s2). 

Thus,  by  generalization,  F  is  contracting. 

Conversely,  suppose  that  F  is  contracting. 

Let  /  be  a  partial  function  such  that  for  any  s  £  dom  F  and  every  r  £  T, 

f(s  \  {r7  I  t'  2  t},  r)  ~  (fl  {F(s')  |  s'  £  dom  F  and  d(s,  s')  2  {2  \  t'  A  r}})(r). 

Assume  s  £  dom  F  and  r  £  T. 

Let  X  =  {s'  |  s'  £  dom  F  and  d(s,  s')  2  {2  |  r7  A  r}}. 

Then,  by  the  generalized  ultrametric  inequality,  for  every  Si,  s2  £  X , 
d(si,s2)  2  {t7  I  r 7  A  r}. 

And  since  F  is  contracting,  for  every  si,  s2  £  X, 
d(2(si),F(s2))  2  {2  I  r7  A  r}. 

Thus, 

f|{d(F(si),F(s2))  |  Si,s2  e  A}  D  {r7  |  r7  A  r}. 

However,  by  Proposition  2.13, 

n  (f(s7)  1  s7  g  x}  =  f(s)  r  n  (Ws  o,  f(S2))  i  Sl,  S2  e  a}. 

and  hence, 

F(s)(r)  ~  (n  {F(s7)  |  s7  €  A})(r) 

-  /(s  I"  {2  |  r7  A  r},r). 

Thus,  by  generalization,  F  is  causal.  □ 
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4.2  Strictly  contracting  functions 


Following  the  same  line  of  reasoning,  one  might  expect  that  a  component  is  strictly  causal  just  as  long  as 
any  two  possible  output  signals  differ  later,  if  at  all,  than  the  signals  that  produced  them  (see  [27,  p.  36]). 

We  say  that  F  is  strictly  contracting  if  and  only  if  for  any  Si,  S2  £  dom  F  such  that  si  ^  s2, 

^(f{s1),F(s2))  D  d(si,s2). 

The  following  is  immediate: 

Proposition  4.2.  If  F  is  strictly  contracting,  then  F  is  contracting. 

In  [44,  p.  484],  Naundorf  defined  strictly  causal  functions  as  the  functions  that  we  here  call  strictly 
contracting,  and  in  [33,  def.  6],  that  definition  was  rephrased  using  the  generalized  distance  function  to 
explicitly  identify  strictly  causal  functions  with  the  strictly  contracting  functions.  But  the  relationship 
between  the  proposed  definition  and  the  classical  notion  of  strict  causality  was  never  formally  examined. 
The  next  proposition  implies  that,  in  fact,  the  two  are  not  the  same. 

Proposition  4.3.  If  F  is  strictly  contracting,  then  F  has  at  most  one  fixed  point. 

Proof.  Suppose  that  F  is  strictly  contracting. 

Suppose,  toward  contradiction,  that  si  and  s2  are  two  distinct  fixed  points  of  F .  Then 
d(F(s1),F(s2))  =  d(si,s2), 
obtaining  a  contradiction. 

Thus,  F  has  at  most  one  fixed  point.  □ 

By  Proposition  4.3,  the  function  of  Example  3.9,  as  well  as  that  of  Example  3.10,  is  not  strictly 
contracting.  By  the  next  theorem,  neither  is  the  function  of  Example  3.8. 

Assume  ACS. 

Theorem  4.4.  If  (X,  2z?  (T,  ^),D,T,  d)  is  non-empty  and  spherically  complete,  then  every  strictly 
contracting  function  on  X  has  exactly  one  fixed  point. 

Theorem  4.4  follows  immediately  from  the  fixed-point  theorem  of  Priess-Crampe  and  Ribenboim  for 
strictly  contracting  functions  on  spherically  complete  generalized  ultrametric  spaces  (see  [49,  thm.  1]), 
which  is  sometimes,  and  perhaps  a  little  too  liberally,  referred  to  as  a  generalization  of  the  Banach 
Fixed-Point  Theorem.  The  following,  which  follows  immediately  from  another  theorem  of  Priess-Crampe 
and  Ribenboim  (e.g.,  see  Banach’s  Fixed  Point  Theorem  in  [58]),  justifies  the  use  of  the  stronger  property 
of  spherical  completeness  in  place  of  the  standard  property  of  Cauchy-completeness  used  in  the  latter: 

Theorem  4.5.  If  ( T,  A)  is  totally  ordered,  then  (X,  Jzf  (T,  ^),D,T,  d)  is  non-empty  and  spherically 
complete  if  and  only  if  every  strictly  contracting  function  on  X  has  a  fixed  point. 

It  will  later  follow  from  Theorem  5.5  and  Example  5.8  that  the  hypothesis  of  (T,  <)  being  totally  ordered 
in  Theorem  4.5  cannot  be  discarded. 

Our  next  example  shows  that  even  the  strictly  causal  functions  that  do  have  exactly  one  fixed  point  need 
not  be  strictly  contracting. 
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Example  4.6.  Suppose  that  T  =  {— 00}  U  Z,  and  A  is  the  standard  order  on  {—00}  U  Z. 
Let  v  be  a  value  in  V. 

Let  F  be  a  function  on  S  such  that  for  every  s  £  S  and  every  r  £  T, 


F(s)(t) 


undefined 

undefined 

undefined 


if  r  =  —00; 

if  r  ^  —00  and  —00  ^  dom  s; 

if  r  ^  —00,  —00  £  dom  s,  and  r  —  Is  dom  s; 

otherwise. 


Clearly,  F  is  strictly  causal,  and  has  a  unique  fixed  point,  namely  the  empty  signal. 
Let  s_oo,0dd  =  {(Tiv)  I  r  =  —  00  or  r  is  an  odd  integer}. 

Let  S- oo^ven  =  { (r, v)  \  t  —  —oo  or  t  is  an  even  integer}. 

Then 


d(T\s_00, odd)  :  F (S—oq^ even)  )  —  d(s_00jodd;  £  —  oo,even); 

and  thus,  F  is  not  strictly  contracting. 

A  less  contrived  example  of  a  traditionally  strictly  causal  system  that  has  a  unique  behavior,  but 
nevertheless  cannot  be  modelled  using  a  strictly  contracting  function,  is  a  continuous-time  dynamical 
system  specified  in  terms  of  an  ordinary  differential  equation  of  the  form 

s(*)  =  f{s(t),t ), 

with  t  a  non-negative  real  number,  and  s(0)  =  v  for  some  value  v.  This  is  really  more  of  a  declarative 
specification  that  we  typically  conceptualize  as  a  component  in  feedback  realizing  the  function 

F(s)(t)=v  +  [  f(s(t'),t')dt' . 

Jo 

We  can  then  identify  the  source  of  the  problem  to  be  the  integrator,  which  although  strictly  causal  in  the 
traditional  sense,  cannot  be  modelled  by  a  strictly  contracting  function.  And  this  would  seem  to  cast 
dynamical  systems  of  this  kind  outside  the  range  of  the  fixed-point  theory  of  Section  5.  Nevertheless,  when 
computing  a  numerical  solution  to  the  differential  equation,  one  is  effectively  transforming  the  component 
realizing  F  into  a  discrete-event  component  that  progresses  in  discrete  steps,  as  dictated  by  the  particular 
solver  in  use,  and  does  in  fact  realize  a  strictly  contracting  function  (see  also  [30]). 

Parenthetically,  we  note  that  a  discrete-time  dynamical  system  specified  in  terms  of  a  recurrence  relation  of 
the  form 

s(n  +  l)  =  f{s(n),n), 

with  n  a  natural  number,  and  s(0)  =  v  as  before,  always  defines  a  strictly  contracting  function. 

What  is  then  the  use,  if  any,  of  strictly  contracting  functions  in  a  fixed-point  theory  for  strictly  causal 
functions?  The  next  couple  of  theorems  are  key  in  answering  this  question. 

Theorem  4.7.  If  ( T,  A)  is  totally  ordered,  and  (dom  F,  Jz?  (T,  A),  D,  T,  d)  is  non-empty  and  spherically 
complete,  then  F  is  strictly  contracting  if  and  only  if  for  every  causal  function  F'  from  ran  F  to  dom  A, 

F'  o  F  has  a  fixed  point. 
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Proof.  Suppose  that  (T,  -<)  is  totally  ordered,  and  (dom  F,  J2?  (T,  ^),  D,  T,  d)  is  spherically  complete. 

If  F  is  strictly  contracting,  then,  by  Theorem  4.1,  for  every  causal  function  F'  from  ran  F  to  dom  F,  F'  o  F 
is  strictly  contracting,  and  thus,  by  Theorem  4.4,  has  a  fixed  point. 

Conversely,  suppose  that  F  is  not  strictly  contracting. 

Then  there  are  si,  s2  G  dom  F  such  that  Si  7^  s2,  but 

d(F(s1),F(s2))  ~f>  d(si,s2). 

And  since  (T,  A)  is  totally  ordered, 

d(a1;a2)  3d(F(Sl),F(s2))  (10) 


Let  F'  be  a  function  from  ran  F  to  dom  F  such  that  for  every  s  £  ran  F, 


F'(s) 


si  if  d(F(s2),a)  D  d(F(si),F(s2)); 
s2  otherwise. 


Assume  s) ,  s2  £  ran  F. 

Since  (T,  ■<)  is  totally  ordered,  either 

d{F{si),F(s2))  2  d(s'1,s'2), 
or 

d(si,s'2)  D  d(F(s1),F(s2))- 


If 

d(F(s1),F(s2 ))  D  d(s'1,s2), 
then,  by  (10), 

d(F'(si),F'(4))Dd(Sl,S2) 
2  d(s,1,s2). 


Otherwise, 

d(si,4)Dd(%),%)).  (11) 

Suppose,  toward  contradiction,  that  F' (s', )  7^  F(s2).  Without  loss  of  generality,  assume  that  F(s'1)  =  s\. 
Then 

d(F(s2),s'1)Dd(F(s1),F(s2)).  (12) 

Since  (T,  is  totally  ordered,  by  (11),  (12),  and  Proposition  2.7, 


d(F(s2),s')  Dd(F(Sl),F(a2)). 

Thus,  A(s2)  =  Si,  obtaining  a  contradiction. 
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Figure  2.  A  functional  component  realizes  a  strictly  contracting  function  F  if  and  only  if  the  cascade  of  the 
component  and  any  arbitrary  causal  component  has  a  unique,  well  defined  behaviour  when  arranged  in  a 
feedback  configuration. 


Therefore,  F(s'1)  =  F(s'2),  and  thus, 

d(F(s'),i;i(4))2d(s'1,4). 

Thus,  by  generalization,  F'  is  contracting,  and  hence,  by  Theorem  4.1,  causal.  But  clearly, 
(F'  o  F)(si)  =  s2 


and 


(F'  o  F)(s2)  =  si, 

and  thus,  F'  o  F  does  not  have  a  fixed  point.  □ 

An  informal  but  informative  way  of  reading  Theorem  4.7  is  the  following:  a  functional  component  realizes 
a  strictly  contracting  function  if  and  only  if  the  cascade  of  the  component  and  any  arbitrary  causal  filter 
has  a  unique,  well  defined  behaviour  when  arranged  in  a  feedback  configuration  (see  Figure  2);  that  is,  the 
components  that  realize  strictly  contracting  functions  are  those  functional  components  that  maintain  the 
consistency  of  the  feedback  loop  no  matter  how  we  chose  to  filter  the  signal  transmitted  over  the  feedback 
wire,  as  long  as  we  do  so  in  a  causal  way. 

Under  the  hypothesis  of  (T,  A)  being  totally  ordered,  Theorem  4.7  completely  characterizes  strictly 
contracting  functions  in  terms  of  the  classical  notion  of  causality,  identifying  the  class  of  all  such  functions 
as  the  largest  class  of  functions  that  have  a  fixed  point  not  by  some  fortuitous  coincidence,  but  as  a  direct 
consequence  of  their  causality  properties.  And  under  the  same  hypothesis,  all  such  functions  are  strictly 
causal. 

Theorem  4.8.  If  (T,  A)  is  totally  ordered,  then  if  F  is  strictly  contracting ,  then  F  is  strictly  causal. 

Proof.  Suppose  that  (T,  A)  is  totally  ordered. 

Suppose  that  F  is  strictly  contracting. 

Let  /  be  a  partial  function  such  that  for  any  s  £  dom  F  and  every  r  £  T, 

f(s  \  {V  |  t'  ~<  t},  r)  ~  (fl  {F(s')  |  s'  £  dom  F  and  d(s,  s')  D  {t'  \  t'  ~<  r}})(r). 

Assume  s  £  dom  F  and  r  £  T. 

Let  X  =  {s'  |  s'  £  dom  F  and  d(s,  s')  D  {t'  \  t'  -<  r}}. 

Then,  by  the  generalized  ultrametric  inequality,  for  every  si,  S2  £  X , 

d(si,s2)  2  W  |  t'  -<  t}. 
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And  since  (T,  A)  is  totally  ordered,  and  F  is  strictly  contracting,  for  every  si,  S2  £  A', 
d(A(si),F(s2))  3  {t'  I  t'  A  t}. 

Thus, 

n{d(F(si),F(s2))  |  si,s2  £  X}  D  {/  |  t'  A  t}. 

However,  by  Proposition  2.13, 

n  W)  I  s'  e  X}  =  F(a)  f  fl  (d(F(Sl),  F(s2))  |  Sl,  s2  £  X}. 

and  hence, 

F(s)(t)~( n  {F(s')  I  s'  £  X})(r) 

-  f(s  \  {t  I  t  -<  r},r). 


Thus,  by  generalization,  F  is  strictly  causal.  D 

The  following  shows  that  the  hypothesis  of  (T,  A)  being  totally  ordered  in  Theorem  4.8  cannot  be 
discarded: 

Example  4.9.  Suppose  that  T  =  {0, 1},  and  A  is  the  discrete  order  on  {0, 1}. 

Let  v\,  v[,  V2,  v'2,  and  v  be  five  distinct  values  in  V. 

Let  F  be  a  partial  function  on  S  defined  by  the  following  mapping: 

{  }  {(0,w),(l,w)}; 

{M}  {<0,  u),  <l,v)}; 

{(0,  «i),  <l,«i)}  >->■  {(0,-y),  (l,wi)}; 

{(0,  V2),  (1,^2)}  {(0,-y),  <l,u2)}; 

{(0,u),  i->-  {(0,u),  (l,u)}; 

{(0,u),  (1,^2)}  !->•  {(0,u),  <l,u)}; 

{(0,u),(l,u)}  >->•  {(0,w),(l,w)}. 

Then  (domP,C)  is  a  finite,  and  thus,  trivially,  complete  subsemilattice  of  (S,C),  and  F  is  strictly 
contracting,  but  not  strictly  causal. 

The  implication  of  Theorem  4.7  and  4.8,  we  believe,  is  that,  under  the  hypothesis  of  (T,  A)  being  totally 
ordered,  the  class  of  strictly  contracting  functions  is  the  largest  class  of  strictly  causal  functions  that  one 
can  reasonably  hope  to  attain  a  uniform  fixed-point  theory  for. 

Finally,  if  we  further  require  that  -<  be  well  founded28  on  the  domain  of  any  signal  in  the  domain  of  a 
function,  which  would  effectively  preclude  the  occurrence  of  infinite  descending  causal  chains  in  feedback 
configurations,  then  the  difference  between  a  strictly  causal  function  and  a  strictly  contracting  one  vanishes. 

Theorem  4.10.  If  for  any  s  £  dom  F,  -<  is  well  founded  on  dom  s,  then  if  F  is  strictly  causal ,  then  F  is 
strictly  contracting. 

28  For  every  set  A,  and  every  binary  relation  R  on  A,  R  is  well  founded  on  A  if  and  only  if  for  every  non-empty  S  C  A , 
there  is  a  £  S  such  that  a  is  ft-minimal  in  S. 
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Proof.  Suppose  that  for  any  s  G  dom  F.  -<  is  well  founded  on  dom  s. 

Suppose  that  F  is  strictly  causal. 

Then,  by  Proposition  3.5  and  Theorem  4.1,  F  is  contracting. 

Assume  si,  s2  £  dom  F  such  that  Si  7^  s2. 

Since  F  is  contracting, 

d(F(si),F(s2))  2  d(si,s2). 

Suppose,  toward  contradiction,  that  -<  is  not  well  founded  on  {r  |  Si(r)  s2(r)}.  Then,  by  the  Axiom  of 
Dependent  Choice,  there  is  an  infinite  sequence  (r„  |  n  £  to)  over  {r  |  Si(r)  s2(r)}  such  that  for  every 
n  £  w,  r„+ 1  -<  Tn. 

If 

{r„  |  n  £  uj}  C  dom  si  =  0, 

then  (rn  |  n  £  uj)  is  an  infinite  sequence  over  dom  s2,  and  thus,  -<  is  not  well  founded  on  dom  s2,  obtaining  a 
contradiction. 

Otherwise, 

{rn  |  n  £  uj}  C  dom  si  7^  0. 

Then,  since  -<  is  well  founded  on  dom  si,  there  is  m  £  ui  such  that  rm  is  ^-minimal  in 

{rn  |  n  £  w}  fl  dom  si.  Thus,  (r„  |  m  <n)  is  an  infinite  sequence  over  dom  s2,  and  hence,  -<  is  not  well 

founded  on  dom  s2,  obtaining  a  contradiction. 

Therefore,  ^  is  well  founded  on  {r  |  si(r)  9^  s2(r)}. 

Let  t'  be  a  tag  that  is  ^-minimal  in  {r  |  si(t)  s2(r)}. 

Then 

d(si,s2)  D  {r  |  r  ^  r'}, 
or  equivalently, 

Si  X  {t  I  T  -<  t'}  =  s2  f  {r  I  T  <  t'}. 

Since  F  is  contracting, 

d(F(si),F(s2))  D  {r  |  r  ^  r'}, 

and  since  F  is  strictly  causal,  F{s\)(r')  ~  T1(s2)(r').  Thus,  r'  G  d(F(si),  F(s2)),  and  hence, 
d(F(si),F(s2))  D  d(si,s2). 

Thus,  by  generalization,  F  is  strictly  contracting.  □ 

The  following  is  immediate  from  Theorem  4.10  and  4.8: 

Corollary  4.11.  If  (T,  <)  is  totally  ordered,  and  for  any  s  £  dom  F,  (dom  s,  -<}  is  well  ordered?9 ,  then  F 
is  strictly  causal  if  and  only  if  F  is  strictly  contracting. 

29  An  ordered  set  (P,  G)  is  well  ordered  if  and  only  if  for  every  non-empty  S  C  P,  there  is  p  G  S  such  that  p  is  least  in  (S,  G ) . 


26 


For  example,  the  function  of  Example  3.7  is  not  strictly  contracting,  as  witnessed  by  the  signals 
{{2n+i  >  Arfi-i)  I  n  G  N}  and  {(^,  2n(n-i))  I  n  E  N  and  n  >  2},  but  its  restriction  to,  say,  the  set  of  all 
discrete-event30  signals  is. 

Corollary  4.11,  immediately  applicable  in  the  case  of  discrete-event  systems,  is  most  pleasing  considering 
our  emphasis  on  timed  computation.  It  implies  that  for  all  kinds  of  computational  timed  systems,  where 
components  are  expected  to  operate  on  discretely  generated  signals,  including  all  programming  languages 
and  model-based  design  tools  mentioned  in  the  beginning  of  the  introduction,  the  strictly  contracting 
functions  are  exactly  the  strictly  causal  ones. 


5  Fixed-point  theory 

We  henceforth  concentrate  on  the  strictly  contracting  functions,  and  begin  to  develop  the  rudiments  of  a 
constructive  fixed-point  theory  for  such  functions. 


5.1  Existence 

We  start  by  proving  another  fixed-point  existence  result  for  strictly  contracting  functions,  which  is  similar 
to  Theorem  4.4,  but  has  a  different  premise.  The  proof  is  more  like  Naundorf’s  proof  in  [44],  but,  as  also 
possible  in  the  case  of  the  existence  part  of  Theorem  4.4  (see  [49,  p.  229]),  our  main  theorem  applies  to  a 
more  general  type  of  function. 

Assume  a  partial  endofunction31  F  on  S. 

We  say  that  F  is  strictly  contracting  on  orbits  if  and  only  if  for  any  s  £  dom  F  such  that  s  ^  F(s), 
d(F(s),F(F(s)))  D  d(s,F(s)). 

In  other  words,  F  is  strictly  contracting  on  orbits  just  as  long  as  the  generalized  distance  between  every 
two  successive  signals  in  the  orbit32  of  any  s  £  dom  F  under  F  gets  smaller  and  smaller  along  the  orbit. 

The  following  is  immediate: 

Proposition  5.1.  If  F  is  strictly  contracting,  then  F  is  strictly  contracting  on  orbits. 

Theorem  5.2.  If  (X,  C)  is  a  non-empty,  directed- complete  subsemilattice  of  ( S,C),  then  every  contracting 
function  on  X  that  is  strictly  contracting  on  orbits  has  a  fixed  point. 

Before  we  embark  on  the  proof  of  the  theorem,  we  prove  two  important  lemmas  that  will  be  useful 
throughout  this  section. 

For  every  partial  endofunction  F  on  S,  and  any  s  £  dom  F,  we  say  that  s  is  a  post-fixed  point  of  F  if  and 
only  if  s  C  F(s). 

Lemma  5.3.  If  ( X ,  C)  is  a  subsemilattice  of  (S,  C),  then  for  every  contracting  function  F  on  X ,  and  any 
set  P  of  post-fixed  points  of  F,  if  P  has  a  least  upper  bound  in  ( X ,  C),  then  |_|^  P  is  a  post-fixed  point  of  F. 

30  A  signal  s  is  discrete-event  if  and  only  if  there  is  an  order-embedding  from  (dom  s,  A)  to  (N,  <)  (see  [27]). 

31  A  function  /  is  an  endofunction  if  and  only  if  ran  /  C  dom  f. 

32  For  every  set  A,  every  function  /  on  A,  and  any  a  £  A,  the  orbit  of  a  under  /  is  the  sequence  (/n(a)  |  n  £  uj). 
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Proof.  Suppose  that  (A,  C)  is  a  subsemilattice  of  (S,  C). 

Assume  a  contracting  function  F  on  A,  and  a  set  P  of  post-fixed  points  of  F  that  has  a  least  upper  bound 
in(A,C). 

Assume  s  £  P. 

Since  F  is  contracting, 

d(F(s),F(l\xP))Dd(s,l\xP).  (13) 

By  Proposition  2.14.2  and  (13), 

d((Ux  P)  n  F(a),  (Ux  P )  n  F(Ux  P))  E  d(a, \Jx  P ')•  (14) 

Also,  since  s  is  a  post- fixed  point  of  F,  by  Proposition  2.14.2, 

d(s,  (Ux  P)  n  F{a))  =  d (F{s)  n  s,  F(s)  n  Ux  P ) 

2d(s,\JxP)-  (15) 

By  (14),  (15),  and  the  generalized  ultrametric  inequality, 

d(s,  (Ux  P)  n  F(U  Y  P))  2  d(s,  Ux  P)- 

Then,  by  the  generalized  ultrametric  inequality, 

d(Ux  p,  (Ux  P)  n  ^(Ux  P))  E  d(s,  Ux  P), 

and  thus,  by  Proposition  2.14.1, 

« n  Ux  p  E  (Ux  P)  n  (Ux  P)  n  ^(Ux  P) 

=  (nxp)^F{uxp)- 

However,  since  s  £  P,  sCUYP,  and  thus,  s  n  U  Y  P  =  s-  Thus, 

SF(UXP)FF(UXP) 

FF(\JXP). 

Thus,  by  generalization,  F(U  x  P)  is  an  uPPer  bound  of  P  in  (A',  C).  And  since  Uy  T*  is  the  least  upper 
bound  of  P  in  (A,  C),  Ux  P  —  -P(Ux  P)-  Thus,  U x  P  is  a  post-fixed  point  of  P.  □ 

Lemma  5.4.  If  (A,  C)  is  a  subsemilattice  of  ( S,  C),  then  for  every  contracting  function  F  on  X,  and  any 
s  £  A,  the  following  are  true: 

1.  F(s )  n  F(F(s))  C  F(F(s)  n  F(F(s))); 

2.  if  s  C  F(s),  then  s  C  F(s)  n  F(F(s)). 

Proof.  Suppose  that  (A,  C)  is  a  subsemilattice  of  (S,  C). 

Assume  a  contracting  function  F  on  A,  and  s  £  X. 

Since  F  is  contracting,  by  Proposition  2.14.2, 

d(F(F(s)  n  F(F(s))),  F(F(s)))  2  d(F(s)  n  F(F(s)),  F(s)) 

=  d(F(s)  n  F(F(s)),F(s)  n  F(s)) 

2d  (F(s),F(F(s))), 
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and  thus,  by  Proposition  2.14.1, 

F(s)  n  F(F(S))  E  F(F(s)  n  F(F(S)))  n  F(F(S)) 

E  F(F(s)  n  F(F(S))). 

Thus,  1  is  true. 

Suppose  that  s  E  F(s). 

Since  F  is  contracting, 

d(F(s),F(F(S)))Dd(s,F(S)), 
and  thus,  by  Proposition  2.14.1, 
s  n  F(s)  E  F(s)  n  F(F(s)). 

And  since  s  E  F(s),  sF\  F(s)  =  s,  and  thus, 
s  E  F(s)  n  F(F(s)). 

Thus,  2  is  true.  □ 

Proof  of  Theorem  5.2.  Suppose  that  (A,  E)  is  a  non-empty,  directed-complete  subsemilattice  of  (S,E)- 
Assume  a  contracting  function  F  on  A  that  is  strictly  contracting  on  orbits. 

Let  P  =  {s  |  s  E  F(s)}. 

Let  s  be  a  signal  in  X. 

By  Lemma  5.4.1, 

F(s)  n  F(F(s))  E  F(F(s)  n  F(F(s))), 

and  thus,  P  /  0.  Then,  by  Kuratowski’s  Lemma  (see  [12,  sec.  10.2]),  every  chain  in  (P,  E)  is  contained  in  a 
C-maximal  chain  in  (P,  E)- 

Let  C  be  a  C-maximal  chain  in  (P,  E)  • 

Since  (X,  E)  is  directed-complete,  C  has  a  least  upper  bound  in  (A,  E)- 
We  claim  that  [ _ |  ^  C  is  a  fixed  point  of  F. 

Suppose,  toward  contradiction,  that  |_|x  C  is  not  a  fixed  point  of  F. 

Let  x  =  P(LLy  C)  n  P(P(U.y  C)). 

By  Lemma  5.3,  [_|A  C  E  P(U  x  C),  and  thus,  by  Lemma  5.4.2,  |_|A-  C  Qx. 

Suppose,  toward  contradiction,  that  |J  x  C  =  x.  Since  F  is  strictly  contracting  on  orbits,  and  |_|  Y  C  is  not 
a  fixed  point  of  F, 

d(P(UA-  C),F(F(UX  C)))  D  d(Ux  C,F(\JX  C)).  (16) 

However,  since  x  =  F(|_|Y  n  -^(-^(Uy  &))  and  U  y  ^  =  hy  Proposition  2.14.2, 

d(U*  C, ^(Uy  C))  =  d(P(U.Y  C),\_\x  C ) 

=  d(P(Ux  C),F( Uy  Q  n  F(F(UA  C))) 

=  d(P(UY  c)  n  p(Uy  C),  f(Uy  C)  n  p(p(Uy  <?))) 

2d(F(UxC),F(F(|JA-C))), 
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contrary  to  (16). 

Therefore,  |JX  Cci.  Thus,  x  ^  C.  And  by  Lemma  5.4.1,  x  Q  F(x),  and  thus,  x  £  P.  Thus,  C  U  {#}  is  a 
chain  in  (P,  C),  and  CcCU  {cc},  contrary  to  C  being  a  C-maximal  chain  in  (P,  C). 

Therefore,  |J  x  C  is  a  fixed  point  of  F.  □ 

There  are  two  things  to  notice  here.  First,  the  proof  of  Theorem  5.2  is  inherently  non-constructive,  overtly 
appealing  to  the  Axiom  of  Choice  through  the  use  of  Kuratowski’s  Lemma.  And  second,  there  need  not  be 
only  one  fixed  point;  indeed,  the  identity  function  on  S  is  trivially  causal  and  strictly  contracting  on  orbits, 
yet  every  signal  is  a  fixed  point  of  it. 

The  following  is  immediate  from  Proposition  4.2,  4.3,  and  5.1,  and  Theorem  5.2: 

Theorem  5.5.  If  (X,  C)  is  a  non-empty,  directed- complete  subsemilattice  of  ( S,  C),  then  every  strictly 
contracting  function  on  X  has  exactly  one  fixed  point. 

For  every  strictly  contracting  partial  endofunction  P  on  S  such  that  (dom  P,  C)  is  a  non-empty, 
directed-complete  subsemilattice  of  (S,  C),  we  write  fixP  for  the  unique  fixed  point  of  P. 

The  following  is  immediate  from  Theorem  4.5  and  5.5: 

Corollary  5.6.  If  (T,  A)  is  totally  ordered,  then  if  (X,Q)  is  a  directed-complete  subsemilattice  of  { S,C), 
then  (X,Hf  (T,  ^),D,T,  d)  is  spherically  complete. 

Example  2.18  showed  that,  even  under  the  hypothesis  of  (T,  A)  being  totally  ordered,  a  directed-complete 
semilattice  of  signals  that  is  not  a  subsemilattice  of  (S,  C)  need  not  be  spherically  complete.  The  following 
shows  that  a  subsemilattice  of  (S,  C)  that  is  not  directed-complete  need  not  be  spherically  complete  either: 

Example  5.7.  Suppose  that  T  =  N,  and  A  is  the  standard  order  on  N. 

Suppose  that  V  is  a  singleton  set. 

Let  X  =  {{0}  x  V,  {0, 1}  x  V,  {0, 1, 2}  x  V, . . .}. 

(X,  C)  is  totally  ordered,  and  thus,  trivially,  a  subsemilattice  of  (S,  C). 

Let  C  =  {{s  |  s  £  X  and  d(s,  {m  \  m  <  n}  xV)3  {m  \  m  <  n}}  \  n  £  N}. 

The  ordered  set  (C,  C)  is  a  non-empty  chain  of  balls  in  (X,  J?  (T,  A),  D,  T,  d),  but  f)  C  =  0.  Thus, 

(X,  j£f  (T,  A),  D,  T,  d)  is  not  spherically  complete. 

Therefore,  Corollary  5.6  is,  in  a  sense,  tight. 

The  following  shows  that  the  hypothesis  of  (T,  A)  being  totally  ordered  in  Corollary  5.6  cannot  be 
discarded: 

Example  5.8.  Suppose  that  T  =  {0, 1}  x  N,  and  A  is  an  order  relation  on  {0,  1}xN  such  that  for  every 
(zi,tti),  (i2,n2)  £  {0, 1}  x  N, 


(*,  nf)  A  (i2,n2) 


i\  =  *2  and  <  n2- 


Let  v  be  a  value  in  V. 

Let  X  =  {{((0,  to),  v)  |  to  <  n}  \  n  £  N}  U  {T  x  {u}}. 

It  is  not  hard  to  verify  that  (A',  C)  is  a  directed-complete  subsemilattice  of  (S,  C). 
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Let  C  =  {{s  |  s  £  X  and  d(s,  {((0,  m),v)  \  m  <  n})  D  {(0,  m)  \  m  <  n}L)  ({1}  x  N)}  |  n  £  N}. 

The  ordered  set  (C,  C)  is  a  non-empty  chain  of  balls  in  (X,  ££  (T,  X),  D,  T,d),  but  fj  (7  =  0.  Thus, 

(X,  ££  (T,  A),  D,  T,  d)  is  not  spherically  complete. 

This  has  two  notable  consequences.  First,  by  Theorem  5.5,  the  hypothesis  of  (T,  A)  being  totally  ordered 
in  Theorem  4.5  cannot  be  discarded.  And  second,  Theorem  4.4  and  5.5  are  incomparable  with  respect  to 
deduction;  that  is,  one  cannot  deduce  Theorem  5.5  from  Theorem  4.4,  nor  Theorem  4.4  from  Theorem  5.5. 


5.2  Construction 

Although  theoretically  pleasing,  mere  existence  of  fixed  points  is  practically  moot.  Theorem  5.2  and  5.5, 
just  like  Theorem  4.4,  offer  little  if  no  means  of  deductive  reasoning  about  the  fixed  points  ascertained  to 
exist.  And  unless  we  construct  these  fixed  points,  we  can  have  little  insight  into  how  they  relate  to  the 
operational  behaviour  of  actual  systems. 

But  how  are  we  to  construct  these  fixed  points?  Theorem  A. 2  and  A. 4  seem  to  render  standard  fixed-point 
theories  of  ordered  sets  and  metric  spaces  more  or  less  irrelevant.  At  the  same  time,  it  may  well  be  that  the 
relevant  fixed-point  theorem  of  Priess-Crampe  and  Ribenboim  is  independent  of  the  theory  of  generalized 
ultrametric  spaces  in  the  classical  Zermelo-Fraenkel  set  theory  without  choice,  thus  lacking  a  constructive 
proof  altogether.33 

The  answer  lies  in  the  non-constructive  proof  of  Theorem  5.2.  Indeed,  the  proof  contains  all  the  ingredients 
of  a  transfinite  recursion  facilitating  the  construction  of  a  chain  that  may  effectively  substitute  for  the 
maximal  one  only  asserted  to  exist  therein  by  an  appeal  to  Kuratowski’s  Lemma.  We  may  start  with  any 
arbitrary  post-fixed  point  of  the  function  F .  and  iterate  through  the  function  \x  :  X  .  F{x )  n  F{F(x))  to 
form  an  ascending  chain  of  such  points.  Every  so  often,  we  may  take  the  supremum  of  all  signals 
theretofore  constructed,  and  resume  the  process  therefrom,  until  no  further  progress  can  be  made.  Of 
course,  the  phrase  “every  so  often”  is  to  be  interpreted  rather  liberally  here,  and  certain  groundwork  is 
required  before  we  can  formalize  its  transfinite  intent. 

We  henceforth  assume  some  familiarity  with  transfinite  set  theory,  and  in  particular,  ordinal  numbers.  The 
unversed  reader  may  refer  to  any  introductory  textbook  on  set  theory  for  details  (e.g.,  see  [15]). 

Assume  a  subsemilattice  ( X ,  C)  of  (S,  C),  and  a  function  F  on  X. 

We  write  lm2  F  for  a  function  on  X  such  that  for  any  s  £  X, 

(lm2  F)(s)  =  F(s)  n  F(F(s)). 

In  other  words,  lm2F  is  the  function  \x  :  X  .  F( x)  n  F(F(x)). 

Assume  a  directed-complete  subsemilattice  (X,  C)  of  (S,  C),  a  contracting  function  F  on  X,  and  a 
post-fixed  point  s  of  F. 

We  let 

(lm2  F)°(s)  =  s, 
for  every  ordinal  a , 

(lm2E)Q+1(s)  =  (lm2F)((lm2F)“(a)), 

33  A  purportedly  constructive  proof  for  some  variant  of  the  fixed-point  theorem  of  Priess-Crampe  and  Ribenboim  was 
presented  in  [20].  However,  the  proof  covertly  appeals  to  the  Axiom  of  Choice  through  a  potentially  transfinite  sequence  of 
choices. 
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and  for  every  limit  ordinal  A, 


(lm2  F)A(s)  =  |_lx  {(lm2  F)a(s)  |  a  £  A}. 

The  following  implies  that  for  every  ordinal  a,  (lm2 F)a(s)  is  well  defined: 

Lemma  5.9.  If  (X,  C)  is  a  directed- complete  subsemilattice  of  ( S,  C),  then  for  every  contracting  function 
F  on  X,  any  post-fixed  point  s  of  F,  and  every  ordinal  a, 

1.  (lm2f)“(s)Ef((lm2F)“(s)); 

2.  for  any  j3  £  a,  (lm2 F)^(s)  C  (lm2F)“(s). 

Proof.  Suppose  that  (X,  C)  is  a  directed-complete  subsemilattice  of  (S,  C), 

Assume  a  contracting  function  F  on  X,  a  post-fixed  point  s  of  F,  and  an  ordinal  a. 

We  use  transfinite  induction  on  the  ordinal  a  to  jointly  prove  that  1  and  2  are  true. 

If  a  =  0,  then  (lm2F)“(s)  =  s.  Thus,  1  is  trivially  true,  whereas  2  is  vacuously  true. 

Suppose  that  there  is  an  ordinal  /3  such  that  a  =  f3  +  1. 

Then 

(lm2  F)a(s)  =  (lm2F)((lm2F)/3(s)) 

=  F((lm2F)/3(s))  n  F(F((lm2F)/3(s))).  (17) 

Thus,  by  Lemma  5.4.1,  1  is  true. 

For  every  7  £  a,  either  7  =  /?,  or  7  £  /3,  and  thus,  by  the  induction  hypothesis, 

(lm2F)7(s)  C  (lm2F)/3(s).  (18) 

Also,  by  the  induction  hypothesis, 

(lm2 F)^(s)  O  F((lm2Ff(s)). 

Thus,  by  Lemma  5.4.2  and  (17), 

(lm2  Ff(s)  O  F((lm2Ff(s))  n  F (F ((lm2  f/(s))) 

=  (lm2  F)a(s).  (19) 

And  by  (18)  and  (19),  (lm2F)7(s)  C  (lm2F)Q(s).  Thus,  2  is  true. 

Otherwise,  a  is  a  limit  ordinal.  By  the  induction  hypothesis,  ({(lm2F)^(s)  |  j3  £  a},  C)  is  totally  ordered, 
and  thus,  {(lm2F)'3(s)  |  /3  £  cr}  is  directed  in  ( X ,  C).  And  since  (. X ,  C)  is  directed-complete, 

{(lm2F)^(s)  |  f}  £  a}  has  a  least  upper  bound  in  (A',  C),  and 

(lm2F)a(s)  =  \Jx  {(lm2Ff(s)  \  0  £  a}. 

Thus,  2  is  trivially  true. 

By  the  induction  hypothesis,  for  every  /3  £  a,  (lm2F)/3(s)  C  F((lm2 F)/3(s)).  Thus,  by  Lemma  5.3,  1  is 
true.  □ 
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By  Lemma  5.9.2,  and  a  simple  cardinality  argument,  there  is  an  ordinal  a  such  that  for  every  ordinal  ft 
such  that  a  £  ft,  (lm2F)/3(s)  =  (lm2  F)“(s).  In  fact,  for  every  directed-complete  subsemilattice  ( X ,  C)  of 
(S,  C) ,  there  is  a  least  ordinal  a  such  that  for  every  contracting  function  F  on  A,  any  post-fixed  point  s  of 
F,  and  every  ordinal  ft  such  that  a  £  ft,  (lm2F)^(s)  =  (lm2F)“(s). 

We  write  oh  ( X ,  C)  for  the  least  ordinal  a  such  that  there  is  no  function  p  from  a  to  A'  such  that  for  every 
ft,  7  £  a,  if  ft  £  7,  then  p(ft)  C  <^(7). 

In  other  words,  oh  (X,  C)  is  the  least  ordinal  that  cannot  be  orderly  embedded  in  (A',  C),  which  we  may 
think  of  as  the  ordinal  height  of  (A,  C).  Notice  that  the  Hartogs  number  of  A'  is  an  ordinal  that  cannot  be 
orderly  embedded  in  (A',  C),  and  thus,  oh  (A,  C)  is  well  defined,  and  in  particular,  smaller  than  or  equal  to 
the  Hartogs  number  of  A. 

Lemma  5.10.  If  ( A,  C)  is  a  directed-complete  subsemilattice  (A,  C)  of  ( S,  C),  then  for  every  contracting 
function  F  on  A,  any  post-fixed  point  s  of  F,  and  every  ordinal  a,  if  (lm2  F)a(s)  is  not  a  fixed  point  of 
lm2  F,  then  a  +  2  €  oh  (A,  C) . 

Proof.  Suppose  that  (A,  C)  is  a  directed-complete  subsemilattice  (A,  C)  of  (S,  C). 

Assume  a  contracting  function  F,  a  post-fixed  point  s  of  F,  and  an  ordinal  a. 

Suppose  that  (lm2F)Q(s)  is  not  a  fixed  point  of  lm2F. 

We  claim  that  for  any  ft,  7  £  a  +  2,  if  ft  ^  7,  then 
(lm2  Ff{s)  ±  (lm2F)7(s). 

Suppose,  toward  contradiction,  that  there  are  ft,  7  £  a  +  2  such  that  ft  7^  7,  but 
(lm2  Ff{s)  =  (lm2A)7(s). 

Without  loss  of  generality,  assume  that  ft  £  7.  Since  F  is  contracting,  by  Lemma  5.9.2, 

(lm2  Ff(s)  C  (lm2A)/3+1(s) 

C(lm2F)7(s), 

and  thus, 

(lm2  Ff(s)  =  (lm2  F)p+1{s). 

And  since  ft  £  7  £  a  +  2,  either  ft  £  a,  or  ft  =  a.  Thus,  by  an  easy  transfinite  induction, 

(lm2  F)p(s)  =  (lm2  F)a(s), 

contrary  to  the  assumption  that  (lm2 F)a(s)  is  not  a  fixed  point  of  lm2F. 

Therefore,  for  any  ft,  7  £  a  +  2, 

(lm2  F)^ (s)  =  (lm2F)7(s) 

if  and  only  if  ft  =  7.  Thus,  since  F  is  contracting,  by  Lemma  5.9.2,  there  is  a  function  ip  from  a  +  2  to  A 
such  that  for  every  ft,  7  £  a  +  2,  if  ft  £  7,  then  <p(ft)  C  93(7).  Thus,  by  definition  of  oh  (A,  C), 
a  +  2  £  oh  (A,  C).  □ 

By  Lemma  5.10,  (lm2  F)oh  (s)  is  a  fixed  point  of  lm2  F.  Nevertheless,  (lm2  F)ob  (s)  need  not  be 
a  fixed  point  of  F  as  intended.  For  example,  if  F  is  the  function  of  Example  3.4,  then  for  every  ordinal  a, 
(lm2F)“(0)  =  0,  even  though  0  is  not  a  fixed  point  of  F.  This  rather  trivial  example  demonstrates  how 
the  recursion  process  might  start  stuttering  at  points  that  are  not  fixed  under  the  function  in  question.  If 
the  function  is  strictly  contracting  on  orbits,  however,  progress  at  such  points  is  guaranteed. 
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Lemma  5.11.  If  ( X ,  IZ)  is  a  subsemilattice  of  (S,  CZ),  then  for  every  function  F  on  X  that  is  strictly 
contracting  on  orbits,  s  is  a  fixed  point  of  F  if  and  only  if  s  is  a  fixed  point  of  lm2  F. 

Proof.  Suppose  that  ( X ,  C)  is  a  subsemilattice  of  (S,  C). 

Assume  a  function  F  on  X  that  is  strictly  contracting  on  orbits. 

If  s  is  a  fixed  point  of  F,  then 

s  =  F(s) 

=  F(F(s)), 

and  thus, 

s  =  F(s)nF(F{s)) 

=  (lm2  F)(s). 

Conversely,  suppose  that  s  is  a  fixed  point  of  lm2  F. 

Then,  by  Proposition  2.14.2, 

d(s,  F(s))  =  d((lm2  F)(s),F(s)) 

=  d(F(s)nF(F(s)),F(s)) 

=  d(F(s)  n  F{F(s)),  F(s)  n  F(s)) 

Dd  (F(s),F(F(s))).  (20) 

Suppose,  toward  contradiction,  that  s  is  not  a  fixed  point  of  F.  Then,  since  F  is  strictly  contracting  on 
orbits, 

d{F(s),F(F(s)))  D  d(s,  F(s)), 
contrary  to  (20). 

Therefore,  s  is  a  fixed  point  of  F.  □ 

We  may  at  last  put  all  the  different  pieces  together  to  obtain  a  constructive  version  of  Theorem  5.2. 

Theorem  5.12.  If  (X,  C)  is  a  directed- complete  subsemilattice  (X,  C)  of  ( S,C),  then  for  every  contracting 
function  F  on  X  that  is  strictly  contracting  on  orbits,  and  any  post-fixed  point  s  of  F,  (lm2  F)oh  (s)  is 
a  fixed  point  of  F. 

Proof.  Suppose  that  (X,  C)  is  a  directed-complete  subsemilattice  (X,  C)  of  (S,  C). 

Assume  a  contracting  function  F  that  is  strictly  contracting  on  orbits,  and  a  post-fixed  point  s  of  F. 

Suppose,  toward  contradiction,  that  (lm2  .F)oh  (s)  is  not  a  fixed  point  of  lm2F.  Then,  by 
Lemma  5.10,  oh  (X,  C)  +  2  £  oh  ( X ,  IZ),  a  contradiction. 

Therefore,  (lm2f1)°^A"-^(s)  is  a  fixed  point  of  lm2F.  And  since  F  is  strictly  contracting  on  orbits,  by 
Lemma  5.11,  (lm2  F)oh  (s)  is  a  fixed  point  of  F.  □ 

To  be  pedantic,  Theorem  5.12  does  not  directly  prove  that  F  has  a  fixed  point;  unless  there  is  a  post-fixed 
point  of  F,  the  theorem  is  true  vacuously.  But  if  X  is  non-empty,  then,  by  Lemma  5.4.1,  for  every  s  £  X, 
(lm2F)(s)  is  a  post-fixed  point  of  F. 

The  following  is  immediate  from  Proposition  4.2  and  5.1,  Lemma  5.4.1,  and  Theorem  5.12: 
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Theorem  5.13.  If  (X,  C)  is  a  non-empty,  directed- complete  subsemilattice  of  ( S,  C),  then  for  every 
strictly  contracting  function  F  on  X ,  and  every  s  €  X , 

fixF  =  (lm2F)oh<X’E>((lm2F)(s)). 

This  construction  of  fixed  points  as  “limits  of  stationary  transfinite  iteration  sequences”  is  very  similar  to 
the  construction  of  extremal  fixed  points  of  monotone  operators  in  [11]  and  references  therein,  where  the 
function  iterated  is  not  lm2F,  but  F  itself.  Notice,  however,  that  if  F  preserves  the  prefix  relation,  then 
for  any  post-fixed  point  of  F,  (lm2F)(s)  =  F(s). 

The  astute  reader  will  at  this  point  anticipate  the  following: 

Theorem  5.14.  If  (X,  C)  is  a  non-empty,  directed- complete  subsemilattice  of  ( S,C),  then  for  every 
strictly  contracting  function  F  on  X, 

fix F  =  Ux  {s  |  s  £  X  and  s  C  F(s)}. 

Proof.  Suppose  that  (X,  C)  is  a  directed-complete  subsemilattice  (X,  C)  of  (S,  C). 

Assume  a  strictly  contracting  function  F  onl. 

Assume  a  post-fixed  point  s  of  F. 

By  Lemma  5.9.2,  s  C  (lm2  F)oh  (s),  and  thus,  since  F  is  strictly  contracting,  by  Proposition  4.2  and 
5.1,  Lemma  5.9.2,  and  Theorem  5.12,  s  C  fix  A. 

Thus,  by  generalization,  fixF  is  an  upper  bound  of  {s  |  s  £  X  and  s  C  F(s)j  in  ( X ,  C).  And  since  fixF  is  a 
post-fixed  point  of  F,  for  every  upper  bound  u  of  {s  |  s  €  X  and  s  C  F(s)}  in  (X,  C),  fi xF  C  u.  Thus, 

fixF  =  |_|x  {s  |  s  e  X  and  s  C  F(s)}.  □ 

In  retrospect,  we  find  that  Theorem  5.14  may  be  derived  directly  from  first  principles.  In  particular,  and 
under  the  premise  of  the  corollary,  it  is  easy  to  establish  without  any  use  of  Theorem  5.12  that  for  every 
sex,  sCfixFif  and  only  if  s  C  F(s),  as  the  reader  may  wish  to  verify. 

The  construction  of  Theorem  5.14  is  identical  in  form  to  Tarski’s  well  known  construction  of  greatest  fixed 
points  of  order-preserving  functions  on  complete  lattices  (see  [60,  thm.  1]).  The  question  naturally  arises 
whether  the  dual  construction  might  also  be  of  use  here.  In  particular,  we  might  be  tempted  to  speculate 
that  fixF  =  {s  |  s  €  X  and  F(s)  Q  s}.  The  following  rejects  this: 

Example  5.15.  Suppose  that  T  =  {0, 1},  and  A  is  the  standard  numerical  order  on  {0, 1}. 

Suppose  that  V  =  {?;}. 

Let  F  be  a  function  on  S  defined  by  the  following  mapping: 

0  (->•  {(l,f)}; 

{(0,u)}  (->•  0; 

{(o,  v),  (1,1>)}  0. 

It  is  easy  to  verify  that  F  is  strictly  contracting.  However, 
fixFg{(0,v}}, 
whereas 

F({(0,v)})Q{(0,v)}. 
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Example  5.15  is  also  sufficient  to  dispose  of  any  lingering  suspicion  that  lm2  F  might  be  order-preserving 
under  the  above  premises. 

5.3  Induction 

Having  used  transfinite  recursion  to  construct  fixed  points,  we  may  use  transhnite  induction  to  prove 
properties  of  them.  And  in  the  case  of  strictly  contracting  endofunctions,  which  have  exactly  one  fixed 
point,  we  may  use  Theorem  5.13  to  establish  a  special  proof  rule. 

Assume  PCS. 

We  say  that  P  is  strictly  inductive  if  and  only  if  every  non-empty  chain  in  (P,  C)  has  a  least  upper  bound 
in(P,C). 

Note  that  P  is  strictly  inductive  if  and  only  if  (P,  C)  is  directed-complete  (see  [36,  cor.  2]). 

Theorem  5.16.  If  (X,  C)  is  a  non-empty,  directed-complete  subsemilattice  of  ( S,  C),  then  for  every 
strictly  contracting  function  F  on  X,  and  every  non-empty,  strictly  inductive  P  C  X,  if  for  every  s  £  P, 
(lm2  F)(s)  £  P,  then  fixP  £  P. 

Proof.  Suppose  that  (X,  C)  is  a  non-empty,  directed-complete  subsemilattice  of  (S,C). 

Assume  a  strictly  contracting  function  P  on  A,  and  non-empty,  strictly  inductive  PCX. 

Suppose  that  for  every  s  £  P,  (lm2 P)(s)  £  P. 

Let  s  be  a  signal  in  P. 

By  Lemma  5.4.1,  (lm2  F)(s)  is  a  post-fixed  point  of  F. 

We  use  transfinite  induction  to  prove  that  for  every  ordinal  a ,  (lm2  F)“((lm2  F)(s))  £  P. 

If  a  =  0,  then 

(lm2F)a((lm2F)(s))  =  (lm2  F)(s), 

and  thus,  since  P  is  closed  under  lm2F,  (lm2  F)Q((lm2  F)(s))  £  P. 

If  there  is  an  ordinal  /3  such  that  a  =  j3  +  1,  then 

(lm2P)“((lm2P)(s))  =  (lm2  F)((lm2  P)/3((lm2  F)(s))). 

By  the  induction  hypothesis,  (lm2  F)^((lm2  F)(s))  £  P,  and  thus,  since  P  is  closed  under  lm2F, 
(lm2F)“((lm2F)(s))  e  P. 

Otherwise,  a  is  a  limit  ordinal,  and  thus, 

(lm2  F)°((lm2  F)(s))  =  Ux  {(lm2 F)/3((lm2  F)(a))  \/3£a}. 

By  the  induction  hypothesis, 

{(lm2F)/3((lm2F)(S))  \p£a}CP, 

and  by  Lemma  5.9.2,  ({(lm2 F),3((lm2  F)(s))  |  /3  £  a},E)  is  totally  ordered.  Thus,  since  P  is  strictly 
inductive,  (lm2 F)“((lm2 F)(s))  £  P. 

Therefore,  by  transfinite  induction,  for  every  ordinal  a,  (lm2 F)“((lm2 F)(s))  £  P. 
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By  Theorem  5.13, 


fixF  =  (lm2F)oh<X’->((lm2^)(s)), 

and  thus,  fixF  £  P.  □ 

Theorem  5.16  is  an  induction  principle  that  one  may  use  to  prove  properties  of  fixed  points  of  strictly 
contracting  endofunctions.  We  think  of  properties  extensionally  here;  that  is,  a  property  is  a  set  of  signals. 
And  the  properties  that  are  admissible  for  use  with  this  principle  are  those  that  are  non-empty  and  strictly 
inductive.  According  to  the  principle,  then,  for  every  strictly  contracting  function  F  on  any  non-empty, 
directed-complete  subsemilattice  of  (S,C),  every  non-empty,  strictly  inductive  property  that  is  preserved 
by  lm2  F  is  true  of  fixF. 

It  is  interesting  to  compare  this  principle  with  the  fixed-point  induction  principle  for  order-preserving 
functions  on  complete  partial  orders  (see  [59]),  which  we  will  here  refer  to  as  Scott-de  Bakker  induction , 
and  the  fixed-point  induction  principle  for  contraction  mappings  on  complete  metric  spaces  (see  [53]), 
which  we  will  here  refer  to  as  Reed-Roscoe  induction  (see  also  [56],  [55],  [25]). 

For  a  comparison  between  our  principle  and  Scott-de  Bakker  induction,  let  F  be  a  function  of  the  most 
general  kind  of  function  to  which  both  our  principle  and  Scott-de  Bakker  induction  apply,  namely  an 
order-preserving,  strictly  contracting  function  on  a  pointed,  directed-complete  subsemilattice  (A',  C)  of 
(S,  C).  Now  assume  a  property  PCX.  If  P  is  admissible  for  use  with  Scott-de  Bakker  induction,  that  is, 
closed  under  suprema  in  (A,  C)  of  arbitrary  chains  in  (P,  C),  then  {s  |  s  £  P  and  s  C  P(s)}  is  non-empty 
and  strictly  inductive.  And  if  P  is  closed  under  P,  then  {s  |  s  £  P  and  s  C  F(s)}  is  trivially  closed  under 
lm2P.  Therefore,  given  any  reasonable  property-specification  logic,  our  principle  is  at  least  as  strong  a 
proof  rule  as  Scott-de  Bakker  induction.  At  the  same  time,  the  often  inconvenient  requirement  that  a 
property  P  that  is  admissible  for  use  with  Scott-de  Bakker  induction  contain  the  least  upper  bound  in 
(A,  C)  of  the  empty  chain,  namely  the  least  element  in  (A,  C),  and  the  insistence  that  the  least  upper 
bound  of  every  non-empty  chain  in  (P,  C)  be  the  same  as  in  (A,  C)  make  it  less  likely  that  every  property 
true  of  fix  P  that  can  be  proved  using  our  principle  can  also  be  proved  using  Scott-de  Bakker  induction. 

For  this  reason,  we  are  inclined  to  say  that,  given  any  reasonable  property-specification  logic,  our  principle 
is  a  strictly  stronger  proof  rule  than  Scott-de  Bakker  induction,  in  the  case,  of  course,  where  both  apply. 

The  relationship  between  our  principle  and  Reed-Roscoe  induction  is  less  clear.  (S,Jf  (T,  A),  D,  T,  d)  being 
a  generalized  ultrametric  space  rather  than  a  metric  one,  it  might  even  seem  that  there  can  be  no  common 
ground  for  a  meaningful  comparison  between  the  two.  Nevertheless,  it  is  possible  to  generalize 
Reed-Roscoe  induction  in  a  way  that  extends  its  applicability  to  the  present  case,  while  preserving  its 
essence.  According  to  the  generalized  principle,  then,  for  every  strictly  contracting  function  P  on  any 
Cauchy  complete,  non-empty,  directed-complete  subsemilattice  of  (S,  C)  such  that  every  orbit  under  P  is  a 
Cauchy  sequence,  every  non-empty  property  closed  under  limits  of  Cauchy  sequences  that  is  preserved  by 
P  is  true  of  fixP.  One  similarity  between  this  principle  and  our  own,  and  an  interesting  difference  from 
Scott-de  Bakker  induction,  is  the  lack  of  an  explicit  basis  for  the  induction;  as  long  as  the  property  in 
question  is  non-empty,  there  is  some  basis  available.  In  terms  of  closure  and  preservation  of  admissible 
properties,  however,  the  two  principles  look  rather  divergent  from  one  another.  For  example,  the  property 
of  a  signal  having  only  a  finite  number  of  events  in  any  finite  interval  of  time  is  Cauchy  complete,  but  not 
strictly  inductive.  On  the  other  hand,  by  Lemma  5.4.1  and  Theorem  5.14,  our  principle  is  better  fit  for 
proving  properties  that  are  closed  under  prefixes,  such  as,  for  example,  the  property  of  a  signal  having  at 
most  one  event  in  any  time  interval  of  a  certain  fixed  size.  And  for  this  reason,  we  suspect  that,  although 
complimentary  to  the  generalized  Read-Roscoe  induction  principle  in  theory,  our  principle  might  turn  out 
to  be  more  useful  in  practice,  what  can  of  course  only  be  evaluated  empirically. 

Finally,  we  note  that  another  simple  proof  rule  may  be  associated  with  the  construction  of  Theorem  5.14, 
which  is  nothing  more  than  rephrasing  the  theorem  to  assert  that  any  post-fixed  point  of  A  is  a  prefix  of 
fix  A.  In  the  context  of  order-preserving  functions  on  complete  lattices,  this  is  known  as  the  coinduction 
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proof  method  (see  [41],  [57]).  Its  dual,  known  as  Park’s  principle  of  fixpoint  induction  (see  [47]),  is  not 
valid  in  our  setting,  as  demonstrated  in  Example  5.15. 


5.4  Convergence 

From  a  computational  point  of  view,  Theorem  5.12  and  5.13  are  not  entirely  satisfying.  The  transfinite 
iteration  sequence  of  post-fixed  points  constructed  may  grow  arbitrarily  long  en  route  to  the  fixed  point. 
For  every  non-empty,  directed-complete  subsemilattice  (A',  C)  of  (S,  C),  the  length  of  the  sequence  will  of 
course  be  bounded  by  oh  (A,  C).  But  for  every  ordinal  a ,  it  is  easy  to  come  up  with  a  strictly  contracting 
endofunction  F  and  a  post-fixed  point  s  of  F  such  that  for  any  /?  £  a,  (lm2 F)^(s)  C  (lm2  F)/3+1(s).  And 
this  is  one  obstacle  to  using  these  theorems  as  effective  procedures  for  “computing”  the  sought  fixed  point. 
Of  course,  the  latter  may  very  well  be  an  infinite  object,  and  we  understand  “computing”  that  object  as  a 
process  of  successive  approximations  converging  to  it.  But  the  notions  of  approximation  and  convergence 
are  formalized  topologically,  and  depend  on  the  topology  chosen.  And  both  the  generalized  distance 
function  and  the  prefix  relation  induce  topologies  on  signals,  each  lending  its  own  perspective  on  the 
problem. 

We  begin  with  the  notion  of  approximation  associated  with  the  generalized  distance  function,  and  start 
probing  into  the  convergence  properties  of  Theorem  5.12  and  5.13  with  the  following  proposition: 

Proposition  5.17.  If  (A,  C)  is  a  directed-complete  sub  semilattice  of  (S,  C),  then  for  every  function  F  on 
A,  any  post-fixed  point  s  of  F,  and  every  ordinal  a  and  ft, 

1.  if  F  is  contracting,  then 

d((lm2  F)Q+1(s),  (lm2  F)p+1(s))  2  d((lm2  F)“(a),  (lm2  Ff(s)); 


2.  if  F  is  contracting  and  strictly  contracting  on  orbits,  and  (lm2i7’)a(s)  ^  (lm2  F)^(s),  then 

d((lm2  F)Q+1(s),  (lm2  Ff+1(s))  D  d((lm2  F)a(s),  (lm2  Ff(s)). 

Proof.  Suppose  that  (A,  C)  is  a  directed-complete  subsemilattice  of  (S,  C). 

Assume  a  function  F  on  A,  and  a  post-fixed  point  s  of  F. 

For  every  ordinal  a ,  let  sa  =  (lm2 F)a(s). 

Assume  ordinals  a  and  /3. 

Suppose  that  F  is  contracting. 

Since  F  is  contracting, 

d (F(F(sa)),F(F(sp)))  2  d (F(sa),F(sp)) 

2  d(sa,  Spf 

Then,  by  Proposition  2.14.2, 

d (F(sa)  n  F(F(sa)),F(sa)  n  F(F(sp)))  2  d(sa,  sp) 

and 

d (F(F(sp))  □  F{sa),F(F{sp))  n  F(sp))  2  d(sa,  sp). 
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Thus,  by  the  generalized  ultrametric  inequality, 

d (F(sa)  n  F(F(sa)),F(sp)  n  F(F(sp)))  D  d(sQ,  sp), 
and  hence,  by  definition  of  lm2  F,  sa ,  and  sp, 

d((lm2F)a+1(s),  (lm2F)/3+1(s))  D  d((lm2  F)“(s),  (lm2F)^(s)). 

Thus,  by  generalization,  1  is  true. 

Suppose  that  F  is  contracting  and  strictly  contracting  on  orbits,  and  sa  ^  sp. 

Since  F  is  contracting,  by  1, 

d(^a+l7  5/3+1 )  =1  d(sa,Sy3). 

Suppose,  toward  contradiction,  that 

Sy3_(_i)  d(sQ,  Sp*).  (21) 

Without  loss  of  generality,  assume  that  a  £  /?.  Then,  by  Lemma  5.9.2, 

Sa  —  ^a+l  1=  Sp  —  Sp-  (22) 

By  Proposition  2.14.2, 

d(s^J  FI  FI  2)  d(sa+i,  Sy3-(-i ) . 

However,  by  (22),  sp  n  sa+i  =  sa+i  and  sp  n  S/3+1  =  sp,  and  thus, 

b(sa+i,  sp')  2  b(sa_(_i ,  sp.\-\ ) .  (23) 

Then,  by  (21),  (23),  and  the  generalized  ultrametric  inequality, 

d(sa,  Sq._|_i)  2)  d(sQ-|-i ,  ) ,  (24) 

and  thus,  by  Proposition  2.14.1  and  (22), 


C  Sp~\- 1  21  Sa  fl  Sa_|_i- 


However,  by  (22),  sa+i  n  s^+i  =  sQ+i  sa  n  sQ+i  =  sa,  and  sa  27  sQ+i,  and  thus,  sa  =  sa+i-  Thus,  sa  is  a 
fixed  point  of  lm2.F,  and  by  an  easy  transfinite  induction,  sa  =  sp,  contrary  to  the  assumption  that 

sa  sp. 

Therefore, 

^(Sck-I-I,  Sy3_|_l  )  Z)  d(sQ,Sy3). 

Thus,  by  generalization,  2  is  true.  □ 

Assume  a  function  F  on  a  non-empty,  directed-complete  subsemilattice  ( X ,  22)  of  (S,  22),  and  consider  the 
first  uj  terms  in  the  transfinite  iteration  sequence  of  lm2  F  starting  from  a  post-fixed  point  s  of  F.  If  F  is 
contracting  and  strictly  contracting  on  orbits,  and  for  every  n  £  oj,  (lm2F)n(s)  7^  (lm2F)"+1(s),  then,  by 
Proposition  5.17.2,  the  sequence  (d((lm2 F)°(s),  (lm2F)1(s)),d((lm2F)1(s),  (lm2F)2(s)), . . .)  is  a  strictly 
descending  chain  in  («£?  (T,  A),  D).  Nevertheless,  the  sequence  ((lm2  F)°(s),  (lm2  F)1(s), . . .)  need  not  be 
Cauchy  (see  Theorem  5.18  and  5.23),  and  thus,  need  not  converge  in  the  topology  induced  by  d  on  X. 
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This  kind  of  convergence  failure  is  a  manifestation  of  Zeno’s  paradox.  This  is  particularly  true  whenever 
(T,  A)  is  totally  ordered,  in  which  case,  (X.  JZ”  (T,  ^),  £>,  T,  d)  is  Cauchy-complete,  indeed  spherically 
complete  (see  Corollary  5.6),  and  therefore,  ((lm2 F)°(s),  (lm2F)1(s), . . .)  fails  to  converge  in  the  related 
topology  exactly  when  |J  {d((lm2  F)n(s),  (lm2F)"+1(s))  |  n  £  uj}  is  a  strict  subset  of  T,  or  equivalently, 
there  is  r  £  T  such  that  for  every  n  £  w,  there  is  t'  -<  r  such  that  (lm2  F)n(s)(T')  (lm2F)"+1(s)(r'). 

By  Lemma  5.9.2  and  Theorem  5.12,  then,  each  term  of  the  sequence  ((lm2  F)°(s),  (lm2F)1(s), . . .)  will 
contribute  at  least  one  new  event  to  the  fixed  point,  each  with  some  tag  t'  -<  r.  For  a  timed  system,  this 
means  that  there  will  be  an  infinite  number  of  events  accruing  before  some  particular  instance  of  time,  a 
variant  of  Zeno’s  paradox. 

This  is  clearly  an  issue  whenever  (lm2  F)u(s)  is  not  a  fixed  point  of  F ,  and  it  may  still  be  an  issue  even 
when  (lm2F)“(s)  is  a  fixed  point  of  F.  But  whenever  the  sequence  ((lm2F)°(s),  (lm2.F)  (s), . . .)  is 
Cauchy,  and  converges  in  the  topology  induced  by  d  on  X,  (lm2F’)w(s)  is  a  fixed  point  of  F. 

Theorem  5.18.  // (T,  X)  is  totally  ordered,  and  (X,C.)  is  a  directed- complete  subsemilattice  of  { S,C), 
then  for  every  contracting  function  F  on  X  that  is  strictly  contracting  on  orbits,  and  any  post-fixed  point  s 
of  F,  if  ((lm2  F)n(s )  |n€w)  is  Cauchy  in  (X,  2z?  (T,  X),  D,  T,  d),  then  (lm2  F)u(s)  is  a  fixed  point  of  F. 

Proof.  Suppose  that  (T,  A)  is  totally  ordered,  and  (X,  C)  is  a  directed-complete  subsemilattice  of  (S,  C). 
Assume  a  contracting  function  F  on  X  that  is  strictly  contracting  on  orbits,  and  a  post-fixed  point  s  of  F. 
For  every  ordinal  a ,  let  sa  =  (lm2F)“(s). 

Suppose  that  (sn  \  n  £  w)  is  Cauchy  in  ( X ,  2z?  (T,  ^),  D,  T,  d). 

Suppose,  toward  contradiction,  that  is  not  a  fixed  point  of  F.  Then,  since  F  is  strictly  contracting  on 
orbits,  by  Lemma  5.11,  is  not  a  fixed  point  of  lm2.F,  and  thus, 

T  D  d(sw,sw+i).  (25) 

Assume  ni,ri2  £  u>. 

Without  loss  of  generality,  assume  that  n\  <  ri2-  Then,  by  Proposition  2.14.2  and  Lemma  5.9.2, 

d(s„i,  Su)  d(s  n2  I”!  Sni  ?  Sri2  ^ 

=  d(sni ,  Sn2  ) 


and 


d(sni,  So;+i)  2  d(s  n 2  fl  Sn\  ;  Sri2  C  ^w-f-l) 

=  d(sni ,  Sn2  ) 

and  thus,  by  the  generalized  ultrametric  inequality, 

^(Sq;  ,  ^  d(sni ,  s„2). 

Thus,  by  generalization  and  (25),  (sn  |  n  £  w)  is  not  Cauchy  in  {X,J£  (T,  A),  D,  T,  d),  contrary  to  our 
assumption. 

Therefore,  is  a  fixed  point  of  F .  jgj 

The  following  is  immediate  from  Proposition  5.1  and  Theorem  5.18: 
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Theorem  5.19.  If  (T,  ■<)  is  totally  ordered,  and  (X,  C)  is  a  non-empty,  directed- complete  subsemilattice  of 
(S,  E),  then  for  every  strictly  contracting  function  F  on  X ,  and  every  s  £  X,  if  ((lm2  F)n(s)  \  n  £  ui)  is 
Cauchy  in  (X,  3C  (T,  X),  D,  T,  d),  then 

fix  F  =  (lm2  F)w((lm2  F)(s)). 

The  following  shows  that  the  hypothesis  of  (T,  X)  being  totally  ordered  in  Theorem  5.18  and  5.19  cannot 
be  discarded: 

Example  5.20.  Suppose  that  T  =  {0, 1}  x  to,  and  E  is  an  order  relation  on  {0, 1}  x  w  such  that  for  every 
(h,ni),  (i2,n2)  £  {0, 1}  x  w, 

{i,n i)  ^  {i2,n2)  •£=>  ii  =  i2  and  m  <  n2. 


Let  v  be  a  value  in  V. 

For  every  (i,  n)  £  T,  let  =  {(( j ,  m),v)  \  j  <  i  and  m  £  u>,  or  j  =  i  and  m  <  n}. 

Let  X  =  {s<ijn)  |  (i,  n)  £  T}  U  {T  x  {u}}. 

It  is  not  hard  to  verify  that  (A',  C)  is  a  directed-complete  subsemilattice  of  (S,  C). 
Let  F  be  a  function  on  X  such  that  for  every  (i,  n)  £  T, 

and 


F({Tx{v}})  =  {Tx{v}}. 


It  is  easy  to  verify  that  F  is  strictly  contracting.  But  although  ((lm2 F)"(s(0,o) ))  |  n  £  w)  is  Cauchy  in 
(A,  (T,  X),  D,  T,  d),  (lm2F1)“(s)  is  not  a  fixed  point  of  F. 

In  Banach’s  fixed-point  theorem,  and  any  reasonable  generalization  of  it  (e.g.,  see  [39],  [10]),  it  is  of  course 
not  the  convergence  of  the  orbit  of  s  under  lm2  F,  but  ultimately,  the  convergence  of  the  orbit  of  s  under 
F  that  is  exploited.  It  is  therefore  interesting  to  see  what  the  orbit  of  s  under  lm2F  does  when  the  orbit 
of  s  under  F  converges.  The  following  shows  that  even  when  every  orbit  under  F  is  Cauchy,  and  converges 
in  the  topology  induced  by  d  on  X,  the  orbit  of  s  under  lm2  F  need  not  be  Cauchy,  and  (lm2F)aJ(s)  need 
not  be  a  fixed  point  of  F : 


Example  5.21.  Suppose  that  T  =  u>  +  2,  and  E  is  the  standard  order  on  oj  +  2. 
Let  V\  and  v2  be  two  distinct  values  in  V. 

Let  X  =  {a  x  {«!}  |  a  £  u>  +  2}  U  {a  x  {ui}  U  ((w  +  2)  —  a)  x  {^2}  |  a  £  w  +  2}. 
It  is  easy  to  verify  that  (X,  C)  is  a  directed-complete  subsemilattice  of  (S,  C). 
Let  F  be  a  function  on  X  such  that  for  every  s  £  X  and  every  r  £  T, 

fur  if  t  £  doms  +  1; 

F(s)(r)  ~  . 

v2  otherwise. 


It  is  easy  to  verify  that  F  is  strictly  contracting.  Furthermore,  for  every  s  £  X  and  every  n  >  1, 
Fn{s)  =  (w  +  2)  x  {vi}. 
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However,  for  every  a  £  to  +  2, 

(lm2 F)Q(0)  =  a  x  {iq}, 
and  thus,  (lm2  F)“(0)  is  not  a  fixed  point  of  F. 

Now,  thus  far,  we  have  been  concerned  with  the  effects  of  convergence  relative  to  the  topology  induced  by 
d.  But  ultimately,  what  we  are  really  interested  in  is  convergence  relative  to  a  topology  induced  by  C.  A 
handy  topology  here  is  of  course  the  Scott  topology,  but  the  details  are  not  important.  What  is  important 
is  that,  for  our  purposes,  topological  convergence  can  be  construed  in  terms  of  suprema  of  w-chains.  And 
to  require  that  the  w-chain  ((lm2F)°(s),  (lm2F)1(s), . . .)  converge  to  the  sought  fixed  point  is  to  require 
that  (lm2  F)“(s)  be  that  fixed  point. 

Ideally,  we  would  like  to  impose  some  kind  of  continuity  condition  on  F,  to  require  that  its  value  at  the 
“infinite”  arguments  be  completely  determined  by  its  value  at  the  “finite”  ones.  This  idea  is  inspired  by 
the  Scott-continuity  paradigm,  and  its  merit  is  not  limited  to  convergent  fixed-point  constructions.  But 
whether  this  is  feasible  or  even  meaningful  in  our  context  is  a  research  topic  on  its  own.  Here,  we  only 
consider  a  simple  condition  on  the  domain  of  F. 

Proposition  5.22.  If  ( A ,  C)  is  a  directed- complete  subsemilattice  of  (S,  C),  and  oh  ( A ,  C)  £  w  +  3,  then 
for  every  contracting  function  F  on  X  that  is  strictly  contracting  on  orbits,  and  any  post- fixed  point  s  of  F, 
(lm2  F)“(s)  is  a  fixed  point  of  F . 

Proof.  We  prove  the  contrapositive. 

Assume  a  contracting  function  F  on  X,  and  a  post-fixed  point  s  of  F. 

Suppose  that  (lm2F)‘i,(s)  is  not  a  fixed  point  of  F.  Then,  since  F  is  strictly  contracting  on  orbits,  by 
Lemma  5.11,  (lm2  F)w(s)  is  not  a  fixed  point  of  lm2F.  Thus,  by  Lemma  5.10,  w  +  2  €  oh  (A',  C),  and 
hence,  oh  (A,  C)  ^  w  +  3.  □ 

In  other  words,  ((lm2F)°(s),  (lm2F)  (s), . . .)  will  converge  to  a  fixed  point  of  F  whenever  there  is  no 
ascending  chain  of  length  u>  +  2  in  (A,  C).  Trivial  as  it  may  be,  this  fact  is  of  note  because  of  its  direct 
bearing  on  discrete-event  systems:  if  F  models  a  component  that  operates  on  discrete-even  signals,  then 
(lm2  F)“(s)  is  a  fixed  point  of  F. 

If  we  further  require  that  (T,  X)  be  totally  ordered,  then  we  may  also  reverse  the  implication  of 
Proposition  5.22,  and  moreover,  do  so  in  a  rather  strong  way. 

Theorem  5.23.  If  ( T, -<)  is  totally  ordered,  and  (A,  C)  is  a  directed- complete  subsemilattice  of  ( S,  C), 
then  the  following  are  equivalent: 

1.  oh  (A,  +  3; 

2.  for  every  contracting  function  F  on  X  that  is  strictly  contracting  on  orbits,  and  any  post-fixed  point  s 
of  F,  (lm2  F)u(s)  is  a  fixed  point  of  F. 

Proof.  Suppose  that  (T,  -<)  is  totally  ordered. 

Suppose  that  (A,  C)  is  a  directed-complete  subsemilattice  of  (S,  C). 

If  1  is  true,  then  by  5.22,  2  is  true. 

Conversely,  suppose  that  1  is  not  true.  Then  there  is  a  function  ip  from  w  +  2  to  A  such  that  for  every 
a,  /3  £  to  +  2,  if  a  €  /3,  then  ip(a)  C  <p(/3). 
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Let  F  be  a  function  on  X  such  that  for  any  s  £  X, 


F(s ) 


<^(min  {a  \  a  £  to  +  1  and  <p(a :)  %  s}) 
f(uj  +  1) 


if  {a  |  a  £  w  +  1  and  if  (a)  %  s}  ^  0; 
otherwise. 


Assume  si,S2  6  X  such  that  Si  7^  s2. 
Suppose,  toward  contradiction,  that 
d(F(si),F(s2))  7$  d(si,s2). 
Then,  since  (T,  -<)  is  totally  ordered, 
d(si,  s2)  2  d(F(si),F(s2)). 


Let  a  be  the  unique  ordinal  in  u>  +  2  such  that  <p(a)  =  F(s i). 
Let  (3  be  the  unique  ordinal  in  uj  +  2  such  that  f{(3)  =  -F(s2). 
Then,  by  (26), 

d(si,s2)  D  d(^(a),vj(/3)), 
and  thus,  by  Proposition  2.14.2, 

d(^(a)  n  si,  f(a)  n  s2)  D  d(y>(a), 


(26) 


(27) 


Without  loss  of  generality,  assume  that  a  £  /?.  Then  a  £  u  +  1. 

Suppose,  toward  contradiction,  that  <p(a)  %  s2.  Then,  by  definition  of  F,  a  £  contrary  to  our 
assumption. 

Therefore,  ip(a)  %  s2,  and  thus, 

ip{u)U  Si  =  if(a).  (28) 

By  (27)  and  (28), 

d((/j(a)  n  S!,ip(a))  D  d(<p(a), 

and  thus,  by  Proposition  2.14.1, 

f{a)  n  ip(P)  C  (<p(a)  n  Si)  n  f(a) 

=  ip(a)  n  Si- 

However,  since  a  £  j. 3,  ip(a)  C  <p(P),  and  thus,  f(a)  n  ip(j 3)  =  f(a).  Hence,  <p(a)  =  ip(a)  n  Si,  and  thus, 
ip  (a)  C  sl5  contrary  to  the  definition  of  F. 

Therefore, 

d(F(si),F(s2))  75  d(si,s2). 


Thus,  by  generalization,  F  is  strictly  contracting. 

Trivially,  <^(0)  is  a  post-fixed  point  of  F ,  and  by  an  easy  transfinite  induction,  for  every  a£ul2, 
(lm2  F)a(f(0))  =  <p(a). 
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Suppose,  toward  contradiction,  that  (lm2 i7,)w((^(0))  is  a  fixed  point  of  F.  Then,  since  F  is  strictly 
contracting,  by  Proposition  5.1  and  Lemma  5.11,  (lm2 F)“(y>(0))  =  (lm2 .F)“+1(i£(0)),  contrary  to  the  fact 
that  <p(cj)  C  <p(cu  +  1). 

Therefore,  (lm2  T’)w((/?(0))  is  not  a  fixed  point  of  /,  and  thus,  2  is  not  true.  □ 

The  following  is  immediate  from  the  proof  of  Theorem  5.23: 

Theorem  5.24.  If  (T,  -<)  is  totally  ordered,  and  ( X ,  C)  is  a  non-empty,  directed- complete  sub  semilattice  of 
(S,  C),  then  the  following  are  equivalent: 

1.  oh  ( X ,  C)  £  u  +  3; 

2.  for  every  strictly  contracting  function  F  on  X,  and  every  s  £  X , 

fixF  =  (lm2  T1)“((lm2  F)(s)). 

The  following  shows  that  the  hypothesis  of  (T,  X)  being  totally  ordered  in  Theorem  5.23  and  5.24  cannot 
be  discarded: 

Example  5.25.  Suppose  that  T  =  u>  +  2,  and  A  is  the  discrete  order  on  u  +  2. 

Suppose  that  V  is  a  singleton  set. 

Let  A  —  {cy  X  \  oc  £  ui  -\- *2} . 

It  is  not  hard  to  verify  that  the  ordered  set  (X,  C)  is  a  directed-complete  subsemilattice  of  (S,  C),  and  that 
oh  ( X ,  C)  =  w  +  3.  However,  for  every  contracting  function  F  on  X  that  is  strictly  contracting  on  orbits, 
and  every  s  £  X,  F(s)  is  a  fixed  point  of  F,  as  the  reader  is  invited  to  verify. 

As  a  hint,  notice  that  for  every  a,  /3, 7,  <5  £  oj  +  2,  if  a  €  /3,  then 
d(7  x  V,  S  x  V)  A  d(a  x  V,  /3  x  V) 
if  and  only  if 

{7^}  C  (0  +  1)  -  a. 

6  Discussion 

From  an  academic  standpoint,  the  fixed-point  theory  of  Section  5  is  quite  satisfying.  It  is,  we  believe, 
elegant,  reasonably  abstract,  and  remarkably  general.  Indeed,  it  is  hard  to  see  how  one  could  relax  the 
premise  that  the  domain  of  the  function  be  a  directed-complete  subsemilattice  of  (S,  C)  in  any  reasonable 
way  without  compromising  the  possibility  of  a  constructive  argument.  But  how  meaningful  is  it  in  practice 
to  assume  that  a  component  operates  on  a  directed-complete  subsemilattice  of  (S,  C)?  And  how  accurately 
does  our  fixed-point  construction  model  the  operation  of  a  component  in  feedback?  In  the  absence  of  a 
formal  operational  semantics,  these  questions  are  admittedly  vague,  and  must  be  evaluated  on  informal 
grounds.  Hence  the  discussion. 

Let  us  start  from  the  concept  of  signal.  Definition  2.2  is  inclusive  enough  to  accurately  capture  the  input  or 
output  behaviour  of  any  sort  of  system  that  one  might  sensibly  think  of  as  timed.  Any  sort  of  variation  in 
time,  be  it  continuous,  discrete,  or  even  hybrid,  will  readily  fit  in  it.  The  very  notion  of  time  is  extremely 
versatile:  real  time,  discrete  time,  superdense  time,  they  surely  do  not  exhaust  the  overwhelming  array  of 
options. 
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On  the  grounds  of  such  generality,  we  feel  comfortable  articulating  the  following  thesis:  every  determinate 
single-input,  single-output  timed  system  can  be  modelled  as  a  partial  function  on  signals.  This  is  effectively 
a  definition,  and  thus,  not  really  susceptible  to  formal  arguments.  It  is,  however,  a  plausible  formalization 
of  our  conception  of  what  a  timed  system  is,  and  the  reader  should  find  no  trouble  subscribing  to  it. 

Notice  that  a  modelling  function  need  not  be  defined  at  every  signal.  This  should  come  as  no  surprise.  For 
example,  a  discrete-event  component  is  expected  to  operate  on  a  possibly  infinite  sequence  of  time-stamped 
values,  processing  them  in  the  order  determined  by  their  time  stamps.  Now,  unless  it  has  no  internal  state, 
it  makes  no  sense  feeding  that  component  with  a  set  of  time-stamped  values  that  cannot  be  arranged  into  a 
sequence  according  to  their  time  stamps.  It  is  therefore  unreasonable  to  demand  that  a  function  modelling 
that  component  be  defined  at  any  signal  that  is  not  a  discrete-event  one. 

On  the  other  hand,  the  domain  of  a  modelling  function  is  not  entirely  arbitrary  either.  To  return  to  the 
foregoing  example,  we  are  happy  to  find  that,  for  any  choice  of  tag  set,  discrete-event  signals  form  a 
directed-complete  subsemilattice  of  (S,  C).  In  fact,  they  form  a  directed-complete  lower  set  of  (S,  C).  And 
this,  we  claim,  is  not  incidental  to  the  discrete-event  case,  but  true  of  any  reasonably  specified  domain  of 
operation.  Arbitrary  signals,  well-ordered  signals,  even  bare  streams  of  values,  all  attest  to  our  claim  as 
natural,  common  examples. 

An  interesting  exception  is  the  case  of  total  signals,  that  is,  signals  that  are  defined  over  the  entire  tag  set. 
Completeness  with  respect  to  directed  suprema  is  still  valid  in  that  case,  albeit  trivially  so,  every  directed 
set  of  total  signals  being  a  singleton  one.  But  closure  under  prefixes  fails  dramatically.  And  yet  there  is 
nothing  unreasonable  in  ruling  out  absence  of  event.  For  absence  of  event  is  absurd  when  it  comes  to 
components  that  demand  an  input  value  at  every  time  instance,  such  as,  for  example,  physical  components 
operating  on  continuous  variations. 

Fortunately,  we  can  easily  reduce  the  fixed-point  problem  of  a  strictly  contracting  function  on  the  set  of  all 
total  signals  to  that  of  one  on  that  of  all  signals.  For  example,  let  v  be  a  fixed  value  in  V,  and  H  a  function 
on  S  such  that  for  every  s  £  S  and  r  €  T, 


s(t)  if  r  €  dom  s; 
v  otherwise. 


H  maps  every  signal  to  a  corresponding  total  signal  by  Filing  any  idle  tag  slots  with  the  value  v.  Now 
assume  a  function  F  on  the  set  of  all  total  signals.  If  F  is  contracting  and  strictly  contracting  on  orbits 
then,  F  o  H  is  also  contracting  and  strictly  contracting  on  orbits.  Moreover,  s  is  a  fixed  point  of  F  if  and 
only  if  s  is  a  fixed  point  of  F  o  H .  Hence,  we  can  use  F  o  H,  which  does  satisfy  our  premise,  to  construct 
and  reason  about  the  fixed  points  of  F,  which  does  not.  Notice  that  if  F  is  strictly  contracting,  then  the 
choice  of  v  is  completely  irrelevant.  This  is  not  true  in  the  more  general  case,  however,  where  that  choice 
can  actually  bias  the  fixed-point  construction  process. 

Of  course,  one  might  be  interested  not  in  the  set  of  all  total  signals,  but  in  some  particular  subset  of  it, 
such  as,  for  example,  that  of  all  continuous  signals.  In  that  case,  one  can  accordingly  adjust  the  foregoing 
reduction  to  make  H  not  a  function  from  the  set  of  all  signals  to  that  subset,  but  one  from  the  closure  of 
that  subset  under  prefixes  to  it. 

There  is  a  different,  yet  instructive  way  to  look  at  such  reductions:  we  may  use  the  function  H  to  induce 
an  order  on  the  set  of  total  signals  in  question  that  arranges  that  set  into  a  directed-complete  semilattice 
satisfying  Proposition  2.14  when  n  is  interpreted  as  the  meet  operation  of  that  semilattice.  We  invite  the 
reader  to  sort  out  the  details,  and  muse  over  the  implications  of  this  approach. 

We  go  on  to  discuss  how  our  fixed-point  construction  relates  to  the  actual  operation  of  a  component  in 
feedback.  To  keep  our  discussion  tractable,  we  assume  that  the  systems  under  consideration  are  either 
physically  or  logically  timed,  such  that  the  output  of  each  component  is  built  up  incrementally,  in  step 
with  progress  of  time  in  the  system. 
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Consider  then  a  directed-complete  subsemilattice  (. X ,  C)  of  (S,  C),  and  a  component  that  realizes  a  strictly 
contracting  function  F  on  X,  and  is  configured  in  feedback  as  Figure  1.  Initially,  there  are  no  events  at  the 
input  of  the  component,  which  thus  sets  out  to  produce  the  events  that  make  up  the  signal  F(0).  But  as 
these  events  begin  to  appear  at  the  output  of  the  component,  they  instantly  modify  the  input  that  the 
component  operates  on,  causing  the  component  to  evaluate  anew  what  events  to  produce.  Because  the 
component  realizes  a  strictly  contracting  function,  however,  the  effect  of  this  retroaction  is  discerned  only 
after  the  events  making  up  the  largest  common  prefix  of  F(0)  and  F(F(0))  have  been  produced,  at  which 
point  the  component  is  seen  to  diverge  from  its  original  path,  and  proceed  with  the  events  that  make  up 
the  signal  F(F(0)  n  F(F  ($))),  or  equivalently,  F((lm2  F)(0)).  Iterating  this  kind  of  reasoning,  we  notice 
that  the  transfinite  sequence  ((lm2F)“(0)  |  a  G  oh  ( X ,  C))  is  really  a  trace  of  the  operation  of  the  system. 
Therefore,  we  expect  that  the  events  produced  throughout  the  operation  of  the  system  be  precisely  those 
that  make  up  the  unique  fixed  point  of  F. 

However  informal,  the  preceding  argument  is  still  quite  tenable,  especially  when  the  system  in  question  is 
linearly  timed.  But  turning  the  argument  into  a  rigorous  proof  would  call  for  a  formal  operational 
semantics,  and  is  thus  outside  the  scope  of  this  work. 

Finally,  it  might  seem  natural  to  extrapolate  this  line  of  reasoning  to  the  situation  where  the  realized 
function  F  is  only  contracting  and  strictly  contracting  on  orbits,  in  an  attempt  to  argue  that,  again,  the 
events  produced  throughout  the  operation  of  the  system  are  those  that  make  up  (lm2  F)oh (0).  At 
closer  inspection  though,  we  find  that  the  argument  outlined  above  is  no  longer  sound  under  the  revised 
conditions.  Specifically,  there  is  no  longer  the  guarantee  that  for  every  a  G  oh  (A',  C),  and  after  having 
produced  the  events  of  (lm2  F)“(0),  the  system  will  ever  go  on  to  reach  (lm2  F)a+1  (0).  This  is  perhaps 
best  understood  through  an  example. 

Example  6.1.  Suppose  that  T  =  {0, 1},  and  A  is  the  standard  order  on  {0, 1}. 

Let  V  =  {v}. 

Let  F  be  a  function  on  S  defined  by  the  following  mapping: 

0  i  ^  {(0,v),  (l,u)}; 

{M}  {(0,u)}; 

{(M)}  ^  {(0,v),  (1,1>)}; 

{(0,u),(M)}  {(0,u),(l,u)}. 

It  is  easy  to  verify  that  F  is  contracting  and  strictly  contracting  on  orbits,  and 

(lm2  F)oh  ^S’->  (0)  =  {(0,  v),  (1,  v}}. 

However, 

(lm2F)°(0)  E{(0,u)} 

E  (lm2F)1(0), 

and  {(0,i>)}  is  another  fixed  point  of  F. 

If  the  component  of  the  system  realizes  the  function  F  of  Example  6.1,  then  it  will  initially  set  out  to 
produce  the  events  that  make  up  {(0,u),  (l,i>)}.  However,  just  after  having  produced  its  first  event,  the 
component  will  be  found  operating  on  {(0,z>)},  a  fixed  point  of  F.  Thus,  the  system  will  never  go  on  to 
produce  the  event  (l,u),  what  would  imply  that  the  component  is  actually  able  to  distinguish  between  an 
extraneously  produced  event  and  an  identical  one  produced  by  itself  in  response  to  absence  of  an  event  at 
that  same  time,  and  thus,  cannot  really  realize  a  function  on  S. 
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However  paradoxical,  the  idea  of  a  component  reacting  instantaneously  to  its  own  stimuli  is  commonplace 
in  reactive  systems,  and  its  potential  bearing  on  logically  timed  systems  should  be  thoroughly  thought  out 
before  declared  nonsensical. 


7  Related  work 


Fixed  points  have  been  used  extensively  in  the  construction  of  mathematical  models  in  computer  science. 
In  most  cases,  ordered  sets  and  monotone  functions  have  been  the  more  natural  choice.  But  in  the  case  of 
timed  computation,  metric  spaces  and  contraction  mappings  have  proved  a  better  fit,  and  Tarski’s 
fixed-point  theorem  and  its  variants  have  given  place  to  Banach’s  contraction  principle.  To  our  knowledge, 
the  first  to  use  this  kind  of  modelling  framework  were  Reed  and  Roscoe  in  their  work  on  a  real-time 
extension  of  CSP  (see  [53],  [54]).  Yates  later  used  more  or  less  the  same  methods  to  develop  what  was 
probably  the  first  extensional  model  of  timed  computation:  a  real-time  extension  of  Kahn’s  process 
networks  (see  [61]).  Muller  and  Scholz  introduced  another  such  extension  in  [43],  working  with  metric 
spaces  of  dense  signals  rather  than  timed  streams.  And  a  uniform  framework  encompassing  both  kinds  of 
models  was  presented  in  [28],  [27],  [30]. 

Common  to  all  [53],  [54],  [61],  [43],  [28],  [27],  and  [30]  is  the  requirement  of  a  positive  lower  bound  on  the 
reaction  time  of  each  component  in  a  system.  This  constraint  is  used  to  guarantee  that  the  functions 
modelling  these  components  are  actually  contraction  mappings  with  respect  to  the  defined  metrics.  The 
motivation  is  of  course  the  ability  to  use  Banach’s  fixed-point  theorem  in  the  interpretation  of  feedback, 
but  a  notable  consequence  is  the  absence  of  non-trivial  Zeno  phenomena,  what  has  always  been  considered 
a  precondition  for  realism  in  the  real-time  systems  community.  Even  in  the  verification  literature,  where  it 
has  not  really  been  necessary  to  bound  the  reaction  time  of  a  component,  divergence  of  time  has  been 
demanded  almost  by  default  (e.g.,  see  [5],  [4],  [18],  [6],  [35]).  And  yet  in  modelling  and  simulation,  where 
time  is  represented  as  an  ordinary  program  variable,  Zeno  behaviours  are  not  only  realizable,  but 
occasionally  desirable  as  well.  Simulating  the  dynamics  of  a  bouncing  ball,  for  example,  will  naturally  give 
rise  to  a  Zeno  behaviour,  and  the  mathematical  model  used  to  study  or  even  define  the  semantics  of  the 
simulation  environment  should  allow  for  that  behaviour.  This  is  impossible  with  the  kind  of  metric  spaces 
found  in  [53],  [54],  [61],  [43],  [28],  [27],  and  [30]  (see  [33,  sec.  4.1]).  Even  worse,  it  is  possible  to  come  up 
with  simulation  models  that  do  not  exhibit  any  kind  of  Zeno  behaviour,  and  are  used  to  specify  embedded 
and  distributed  real-time  systems  (see  [66]  and  [14]),  but  consist  of  components  that  cannot  be  handled 
within  the  kind  of  framework  used  in  the  above  references. 

It  is  worthwhile  noting  that  the  requirement  of  time  divergence  is  absent  from  the  real-time  process  calculi 
that  emerged  around  the  same  time  (e.g.,  see  [42],  [63],  [45],  [17]).  The  reason  behind  this  is  that  such  a 
requirement  would  call  for  a  treatment  similar  to  that  of  fairness  or  the  finite  delay  property  in  the 
corresponding  untimed  calculi,  which  has  always  been  problematic  with  traditional  interleaving  theories 
based  on  labelled  transition  systems  (see  [38],  [37]). 

Another  limiting  factor  in  the  applicability  of  the  existing  approaches  based  on  metric  spaces  is  the  choice 
of  tag  set.  The  latter  is  typically  some  unbounded  subset  of  the  real  numbers,  excluding  other  interesting 
choices,  such  as,  for  example,  that  of  superdense  time  (see  [33,  sec.  4.3]). 

Naundorf  was  the  first  to  address  these  issues,  abolishing  the  bounded  reaction  time  constraint,  and 
allowing  for  arbitrary  tag  sets  (see  [44]).  He  defined  strictly  causal  functions  as  the  functions  that  we  here 
call  strictly  contracting,  and  used  an  ad  hoc,  non-constructive  argument  to  prove  the  existence  of  a  unique 
fixed  point  for  every  such  function.  Unlike  that  in  [28],  [27],  and  [30],  Naundorf ’s  definition  of  strict 
causality  was  at  least  sound  under  the  hypothesis  of  a  totally  ordered  tag  set  (see  Theorem  4.8),  but 
nevertheless  incomplete  (e.g.,  see  Example  3.9).  It  was  rephrased  in  [33]  using  the  generalized  distance 
function  to  explicitly  identify  strictly  causal  functions  with  the  strictly  contracting  ones.  This  provided 
access  to  the  fixed-point  theory  of  generalized  ultrametric  spaces,  which,  however,  proved  less  useful  than 
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one  might  have  hoped.  The  main  fixed-point  theorem  of  Priess-Crampe  and  Ribenboim  for  strictly 
contracting  endofunctions  offered  little  more  than  another  non-constructive  proof  of  Naundorf’s  theorem, 
improving  only  marginally  on  the  latter  by  allowing  the  domain  of  the  function  to  be  any  arbitrary 
spherically  complete  set  of  signals,  and  the  few  constructive  fixed-point  theorems  that  we  know  to  be  of 
any  relevance  (e.g.,  see  Proof  of  Theorem  9  for  ordinal  distances  in  [22],  [26,  thm.  43])  were  of  limited 
applicability. 

An  interesting  generalization  of  Naundorf’s  theorem  was  proved  in  [19].  The  overall  approach  is  vaguely 
reminiscent  of  our  effort  to  understand  the  relationship  between  the  generalized  distance  function  and  the 
prefix  relation  on  signals,  and  abstract  from  the  internal  structure  of  the  latter.  But  the  intent  is  to 
eliminate  any  reference  to  generalized  distances,  and  the  proof  is  again  non-constructive. 

A  constructive  fixed-point  theorem  for  a  restricted  class  of  strictly  causal  functions  on  signals  over  a 
superdense  time  domain  was  proved  in  [10].  Although  a  bit  more  generally  applicable,  the  theorem  was 
explicitly  applied  to  so-called  “eventually  delta-causal”  functions,  which  model  components  subject  to  a 
simple  generalization  of  the  bounded  reaction-time  constraint  to  the  case  of  superdense  time. 

There  have  also  been  a  few  attempts  to  use  complete  partial  orders  and  least  fixed  points  in  the  study  of 
timed  systems.  In  [62],  Yates  and  Gao  reduced  the  fixed-point  problem  related  to  a  system  of  so-called 
“Z\-causal”  components  to  that  of  a  suitably  constructed  Scott-continuous  function,  transferring  the  Kahn 
principle  to  networks  of  real-time  processes,  but  once  more,  under  the  usual  bounded  reaction-time 
constraint.  A  more  direct  application  of  the  principle  in  the  context  of  timed  systems  was  put  forward  in 
[31]  and  [32].  A  special  value  was  used  to  make  absence  of  event  explicit,  and  signals  were  constrained  to 
be  defined  on  lower  sets  of  the  tag  set,  making  progress  of  time  part  of  the  semantics  of  a  system.  Strictly 
causal  functions  were  defined  to  be  the  monotone  functions  that  extend  the  domain  of  definition  of  signals, 
and  strictly  causal  functions  that  were  also  Scott-continuous  were  proved  to  have  unique  fixed  points  in 
which  time  diverges.  This  meant  relaxing  the  bounded  reaction-time  constraint  to  allow  for  certain 
components  whose  reaction  time  is  locally  rather  than  globally  bounded.  But  the  proposed  definition  of 
strict  causality  was  still  incomplete,  unable  to  accommodate  components  with  more  arbitrarily  varying 
reaction-times,  such  as  the  one  modelled  by  the  function  of  Example  3.7  restricted  to  the  set  of  all 
discrete-event  signals,  and  ultimately,  systems  with  non-trivial  Zeno  behaviours.  Finally,  a  more  naive 
approach  was  proposed  in  [9],  where  components  were  modelled  as  Scott-continuous  functions  with  respect 
to  the  prefix  relation  on  signals,  creating,  of  course,  all  kinds  of  causality  problems,  which,  however,  seem 
to  have  gone  largely  unnoticed. 

Lastly,  we  mention  Broy’s  work  in  [8],  where  he  proves,  without  the  use  of  “more  sophisticated  theoretical 
concepts  such  as  least  fixpoints,  complete  partially  ordered  sets  or  metric  spaces” ,  that  every  so-called 
“time-guarded”  function  on  timed  streams  has  a  unique  fixed  point,  but  again,  under  the  usual  bounded 
reaction-time  constraint. 


8  Conclusion 

An  interesting  way  to  communicate  the  contribution  of  this  work  is  through  a  comparison,  or  perhaps 
contrast,  with  Kahn’s  seminal  work  on  networks  of  asynchronous  processes  (see  [24]),  much  as  was  done  in 
[61].  Just  as  in  [24],  our  objective  is  ultimately  a  mathematical  semantics  facilitating  the  definition, 
construction,  and  analysis  of  complex  systems.  But  the  systems  we  have  in  mind  are  radically  different 
from  those  considered  in  [24],  setting  up  a  very  different  problem  indeed. 

Kahn  was  interested  in  sequential  processes  that  compute  in  parallel  and  communicate  asynchronously 
through  finite-delay,  first  in,  first  out,  unbounded  queues.  It  was  his  brilliant  insight  to  model  each  process 
as  a  Scott-continuous  function  from  the  complete  partial  order  of  histories  over  its  input  queues  to  that  of 
histories  over  its  output  queues,  and  the  behavior  of  a  network  of  such  processes  as  the  least  solution  to  a 
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system  of  mutually  recursive  equations,  one  for  each  queue.  To  better  motivate  his  presentation,  he 
sketched  a  toy,  ALGOL-like  programming  language  for  such  networks,  which  was  meant  as  a  concrete 
illustration  of  the  proposed  computational  paradigm. 

Our  interest  is  in  components  that  are  also  autonomous,  at  least  conceptually,  but  communicate  through 
timed  signals  rather  than  untimed  streams.  And  unlike  Kahn’s  processes,  these  components  are  very  much 
aware  of  time.  As  a  consequence,  they  can  behave  in  ways  that  cannot  be  modelled  using  any  sort  of 
order-preserving  function.  Thus,  we  can  never  hope  to  find  a  mathematical  semantics  for  systems  made  up 
of  such  components  within  standard  domain  theory,  as  in  [24].  Rather,  we  have  to  build  a  new  theory, 
starting  with  a  fixed-point  theory  for  the  kind  of  functions  used  to  model  them.  Kahn  took  an  established, 
well  understood  mathematical  model,  and  matched  it  with  a  computational  paradigm.  We  already  have 
the  paradigm;  what  we  need  is  the  model. 

Looking  back,  our  fixed-point  theory  is  surprisingly  similar  to  that  of  order-preserving  functions.  In  fact, 
every  feature  of  our  theory  is  characterized  in  a  purely  order-theoretic  fashion.  The  reason  for  this  is  that, 
even  though  strictly  contracting  functions  need  not  be  order-preserving,  systems  made  up  of  components 
that  realize  such  functions  still  build  up  their  behaviour  in  a  monotone  way,  never  invalidating  what  they 
have  already  output,  which  is  possibly  the  only  similarity  between  these  systems  and  those  considered  by 
Kahn  in  [24], 

The  reader  will  likely  protest  here  that,  unlike  [24],  we  have  only  dealt  with  feedback  configurations,  and 
specifically,  only  those  involving  a  single  component  with  a  single  input  and  a  single  output.  This  is  not 
entirely  true  though.  Assuming  a  non-empty  set  C  of  channels  mediating  the  communication  between  the 
individual  components  within  a  system,  and  for  each  channel  c,  a  non-empty  set  Vc  of  values  that  may  be 
communicated  over  c,  we  can  model  a  component  with  more  than  one  input  and  output  again  as  a  partial 
function  on  signals,  but  this  time,  on  signals  whose  values  range  over  the  non-empty,  single-valued  subsets 
of  (J  {{c}  x  Vc  |  c  S  C}.  And  since  every  system  can  be  thought  of  as  a  single  component  receiving  and 
transmitting  over  every  channel,  every  system  is  effectively  amenable  to  our  theory. 

Recursion,  in  the  sense  of  [24],  poses  a  greater  challenge.  In  principle,  it  is  possible  to  extend  the  results  of 
Section  5  to  the  case  of  strictly  contracting  operators  on  strictly  contracting  functions,  suitably  defined,  to 
handle  recursive  schemata  of  the  kind  considered  in  [24] ,  suitably  guarded.  But  as  we  stand,  if  we  were  to 
do  so,  we  would  have  to  relapse,  if  only  in  part,  into  a  composite  view  of  signals,  having  to  peek  under  the 
hood  at  their  individual  events.  And  the  problem  would  become  intractable  if  we  were  to  more  generally 
consider  higher-order  systems,  where  we  would  practically  have  to  adjust  each  result  and  its  proof  to  each 
higher-order  type. 

What  we  need  is  an  abstract  characterization  of  a  class  of  structures  that  will  support  the  development  of 
the  theory,  and  remain  closed  under  the  construction  of  products  and  function  spaces  of  interest,  enabling 
the  treatment  of  arbitrary,  even  higher-order  composition  in  a  more  standard,  uniform  way.  Clauses  1  and 
2  of  Proposition  2.14  have  been  singled  out  precisely  with  this  purpose  in  mind.  Indeed,  we  have  done  well 
to  derive  every  result  of  Section  5  from  these  two  properties  alone,  without  any  reference  whatever  to  the 
internal  structure  of  signals.  Because  of  this,  our  fixed-point  theory  is  actually  perfectly  applicable  to  any 
directed-complete  semilattice  satisfying  clauses  1  and  2  of  Proposition  2.14  when  n  is  interpreted  as  the 
meet  operation  of  that  semilattice  and  d  as  a  generalized  ultrametric  thereon.  But  whether  it  is  necessary 
to  restrict  such  structures  further  or  not  is  still  an  open  question. 

We  conclude  with  a  few  words  on  the  issue  of  determinacy.  From  the  outset,  we  have  insisted  that  a  timed 
system  be  determinate,  down  to  every  constituent  component.  When  it  comes  to  communication  and 
concurrency,  indeterminacy  is  a  very  powerful  semantic  abstraction,  but  one  that  is  mainly  used  when  the 
only  relevant  aspect  of  time  is  order.  It  is  of  course  absurd  to  talk  about  indeterminacy  in  this  sense  here. 
It  is  still  possible,  however,  for  indeterminacy  to  enter  the  scene,  this  time  with  the  intent  of  modelling  the 
uncertainty  in  the  precision  of  timing,  an  issue  of  major  concern  in  any  distributed  system.  Investigating 
the  adaptation  and  application  of  our  methods  in  that  context  is  another  interesting  direction  for  future 
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work. 
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A  Appendix 


We  prove  that  there  is  no  non-trivial  order  relation  that  will  render  every  strictly  contracting  endofunction 
order-preserving,  and  no  metric  function  that  will  render  every  such  endofunction  a  contraction  mapping. 
The  implication  is  that  it  is  impossible  to  directly  apply  the  fixed-point  theory  of  ordered  sets  or  that  of 
metric  spaces  to  the  fixed-point  problem  in  hand. 


A.l  Strictly  contracting  functions  versus  order-preserving  functions 


As  first  pointed  out  in  [62]  and  [61],  there  are  strictly  causal  functions  that  do  not  preserve  the  prefix 
relation  on  signals.  The  following  illustrates  this: 


Example  A.l.  Suppose  that  T  =  [0,  oo),  and  A  is  the  standard  order  on  [0,oo). 
Let  v  be  a  value  in  V. 

Let  f  be  a  function  on  S  such  that  for  every  s  £  S, 


F(s) 


{(1,  w)}  if  for  every  r  £  [0, 1),  r  ^  dom  s; 
0  otherwise. 


Clearly,  F  is  a  strictly  causal  function,  and  it  is  easy  to  verify  that  F  is  in  fact  a  strictly  contracting 
function.  However,  F(0)  %  F({( 0,u)}),  whereas  0  C  { <0,  v) } ,  and  thus,  F  is  not  order-preserving  in  (S,  C). 

The  function  of  Example  A.l  models  a  component  that  operates  like  an  alarm  clock  that  is  set  to  go  off  at 
time  1  unless  it  is  reset  before  that  time,  and  clearly,  fails  to  preserve  the  prefix  relation  on  signals.  As  a 
consequence,  we  cannot  hope  to  use  the  fixed-point  theory  for  order-preserving  functions  to  study  the 
behaviour  of  such  a  component  in  feedback,  at  least  not  if  we  intend  to  use  the  prefix  relation  as  our  order 
relation.  But  what  if  we  are  inclined  to  look  for  a  different  one? 

In  general  terms,  we  may  ask  the  following  question:  Is  there  a  non-trivial  order  relation  on  signals  that 
will  render  all  strictly  causal,  or  more  pertinently,  strictly  contracting  functions  order-preserving?  The 
answer  is  no. 

Assume  ACS. 

Theorem  A. 2.  If  (T,  A)  is  totally  ordered,  and  for  any  s i,  S2  £  X  such  that  s\  4  s 2,  there  are  s\ ,  s2  £  X 
such  that  4  4  s'2  and 


d(4>4)  C  d(si,s2), 

then  for  every  order  relation  ^  C  X  x  X,  every  strictly  contracting  function  on  X  is  order-preserving  in 
( X ,  if  and  only  if  4  is  the  discrete  order  on  X . 

Proof.  Suppose  that  (T,  A)  is  totally  ordered. 

Suppose  that  for  any  si,  s2  £  X  such  that  si  4  s2,  there  are  4,  s2  £  X  such  that  4  4  s2  and 


d(4>4)  3  d(si,s2). 


Assume  an  order  relation  4  C  X  x  X. 

Suppose  that  every  strictly  contracting  function  on  X  is  order-preserving  in  ( X ,  ^). 
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Suppose,  toward  contradiction,  that  there  are  s i,  s2  £  X  such  that  si  ^  s2  and  si  7^  s2.  Then  there  are 
si ,  s2  £  X  such  that  si  7^  s2  and 

d(s,1,  s'2)  D  d(si,  s2).  (29) 


Let  F\  be  a  function  on  X  such  that  for  every  s  £  X, 
si  if  d(si,s)  D  d(si,s2); 


Fi(s)  = 


otherwise. 


Let  F2  be  a  function  on  X  such  that  for  every  s  £  X, 
s2  if  d(si,s)  D  d(si,s2); 


F2(s)  = 


si  otherwise. 


Assume  s'{,  s2  £  X  such  that  s"  7^  s2 . 
Since  (T,  F)  is  totally  ordered,  either 

d(si,s2)  D  d(si',s'2'), 
or 

d(si,  s2)  D  d(si,s2). 


If 

d(si,s2)  D  d(s",s"), 
then,  by  (29), 

d(F1(si'),F1(s"))2d(si,s'2) 
D  d(si,s"). 


Otherwise, 

d(s",s2)  D  d(si,s2).  (30) 

Suppose,  toward  contradiction,  that  F-t  (s'()  7^  Fi(s2).  Without  loss  of  generality,  assume  that  Ft  (s")  =  si- 
Then 

d(si,s")  D  d(si,s2).  (31) 

Since  (T,  A)  is  totally  ordered,  by  (30)  and  (31), 
d(s",  s'2')  0  d(si,  s'/)  D  d(si,  s2), 
and  thus,  by  the  generalized  ultrametric  inequality, 
d(si,s2)  D  d(si,s2). 

Thus,  F-\  (s2)  =  si,  obtaining  a  contradiction. 
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Therefore,  F-\  (s'{)  =  F-\  (s2),  and  since  s "  ^  s2, 


Thus,  by  generalization,  F\  is  strictly  contracting.  And  by  symmetry,  F2  is  strictly  contracting.  Then,  by 
hypothesis,  Fi  and  F2  are  order-preserving  in  (X,  ^).  And  since  Si  ^  s2,  Fi{si)  ^  -Fi(s2)  and 
F2(si)  ^  F2(s2),  and  thus,  ^  s'2  and  s2  ^  s[.  Thus,  .s)  =  s2,  obtaining  a  contradiction. 

Therefore,  for  every  s  1,  s2  £  X,  s\  ^  s2  if  and  only  if  si  =  s2.  Thus,  ^  is  the  discrete  order  on  X. 

Conversely,  if  ^  is  the  discrete  order  on  X,  then,  trivially,  every  strictly  contracting  function  on  X  is 
order-preserving  in  (X,^).  □ 

Note  that  a  more  natural  hypothesis  for  Theorem  A. 2  would  be  to  require  that  {d(si,  s2)  \  Si,s2  £  X}  is 
cofinal  in  (.Sf  (T,  F),  C),  but  the  weaker  assumption  of  there  not  being  a  generalized  distance  that  is 
D-minimal  in  {d(si,s2)  |  si,s2  £  A'}  is  sufficient  to  prove  the  theorem. 

By  Theorem  A. 2,  it  is  impossible,  under  the  pertaining  assumptions,  to  arrange  signals  in  any  non-trivial, 
let  alone  sensible,  ordering  that  is  preserved  by  every  strictly  contracting  function.  Whether  for  every 
particular  strictly  contracting  function  there  is  such  an  ordering  preserved  by  that  function  remains  an 
open  question.  But  a  unified  framework  facilitating  the  representation  of  strictly  contracting  functions  as 
order-preserving  functions  is  out  of  the  question. 

Parenthetically,  we  remark  that  functions  that  do  preserve  the  prefix  relation  on  signals  need  not,  in 
general,  be  strictly  causal  either  (e.g.,  see  Example  3.3). 

A. 2  Strictly  contracting  functions  versus  contraction  mappings 

In  the  same  spirit  as  before,  we  may  ask  the  following  question:  Is  there  a  metric  function  on  signals  that 
will  render  all  strictly  contracting  functions  contraction  mappings?  The  existence  of  such  a  metric  function 
would  be  of  genuine  practical  interest,  for  one  could  then  directly  apply  Banach’s  fixed-point  theorem  to 
solve  the  fixed-point  problem  considered  in  this  work.  But  the  answer  is  still  no. 

Assume  an  infinite  sequence  ( sn  \  n  £  uS)  over  S. 

Lemma  A. 3.  If  (T,  X)  is  totally  ordered,  and  for  every  n  £  ui, 
d(Sn-|-l ;  ^n+2 )  F  d(sn,  Sra-|_i), 

then  the  following  are  true: 

1.  for  every  n  £  to,  and  every  ii,i2  £  to  \  {0}, 

d(Sn  i  )  d(.Sn ,  Sn_|_j2  )  , 

2.  for  every  m,  n2  £  lo  such  that  n±  7^  n2,  and  every  ii,i2  £  u>  \  {0}, 

d(Sni+ii ;  Sn2-|-j2)  — *  d(sni,Sn2). 

Proof.  Suppose  that  (T,  X)  is  totally  ordered. 

Suppose  that  for  every  n  £  w, 

d(sn_f_i ,  sn_|_2 )  £)  d(sn ,  Sn+i ) , 
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Assume  n  £  oj. 

We  use  induction  to  prove  that  for  every  i  £  uj\  {0}, 
d(sn,  —  d(s„,  Sn+l). 

If  i  =  1,  then,  trivially, 

d(sn,sn_(_i)  —  d(sn ,  ) . 

Otherwise,  there  is  j  £  uj\  {0}  such  that  i=  j  +  1.  By  the  induction  hypothesis, 

d(sn,sn-|_j)  —  d(s„,  sra+i).  (32) 

By  hypothesis, 

d(Sn+j,  £72+2)  —  d(sn_|_j  ,  Sn_|_j_|_i) 

^  d(sn?  sn_(-i).  (33) 

Suppose,  toward  contradiction,  that 

^n+l)  d(sn,  ^n+i)*  (34) 

Then,  since  (T,  ■<)  is  totally  ordered,  by  (32),  (33),  (34),  and  Proposition  2.7, 
h(sn,  sn_|_^)  D  d(sn,  Sn+i) j 
obtaining  a  contradiction. 

Therefore,  since  (T,  ■<)  is  totally  ordered, 

h(Sn,  ^72+z)  d(s  725  ^72+1 )  • 

Suppose,  toward  contradiction,  that 

d(sn,  sn+i)  Z>  d(sn,  (35) 

Then,  since  (T,  A)  is  totally  ordered,  by  (33),  (35),  and  Proposition  2.7, 
d(sn,  sn-^-j )  Z)  d(sn,  sn_|_i), 
in  contradiction  to  (32). 

Therefore, 

d(s„,  sn_j_2)  =  d(sn,  sn_|_i). 

Therefore,  by  induction,  for  every  i  £  uj\  {0}, 
d(sn,  Sn+i)  —  d(sn,  Sn_j_i). 


Then,  for  every  ii,  12  S  w  \  {0}, 

d(sn,  )  —  d(sn,  Sn+i) 
—  d(sn,  Sn-\-i2  ) 
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and  thus,  1  is  true. 

Assume  rii,  ?i2  £  tv  such  that  ni  7^  712,  and  i\,  12  £  w  \  {0}. 
Then,  by  1, 

d(srai,  S„2)  d(smin{ni„2},  Smin  {n1,7T.2>+1)- 
Since  n\  <  ri2  and  ii,  t2  £  w  \  {0}, 

min{m,  n2}  +  1  <  min{m  +  ii,  n2  +  *2}- 


(36) 


(37) 


If  rii  +  *i  =  712  +  *2,  then,  trivially, 
d(^7li+ii ;  Sri2+i2  )  73  d(s  n 1 5  ^n2 )  • 

Otherwise,  ni  +  i\  7^  ri2  +  i2-  Then,  by  1, 

i  sn2+i2  )  d(sm;n  {777+7-,  ,772+i2} ,  smin  {777+77  ,772+72}  +  l)‘ 

Thus,  by  (36),  (37),  (38),  and  hypothesis, 

ti(5r7i_)_7i  ,  Sn2+22)  d(S771  ,  St72  )  . 


(38) 


Thus,  by  generalization,  2  is  true.  P: 

Theorem  A. 4.  If  (T,  X)  is  totally  ordered,  and  there  is  an  infinite  sequence  ( sn  \  n  £  tv)  over  X  such  that 
for  every  n  £  tv, 

^(577+1,577+2)  73  c1(St7 ,  S77+1 ) , 

and  sa,  Sb  £  X  such  that  sa  7^  Sb  and  for  every  n  £  tv, 
d(sQ,Sb)  7)  d(s77,  ), 

then  for  every  metric  function 34  d  on  X ,  there  is  a  strictly  contracting  function  on  X  that  is  not  a 
contraction  mapping* 1 2 3 * 5  on  ( X ,  d) . 

Proof.  Suppose  that  (T,  X)  is  totally  ordered. 

Suppose  that  there  is  an  infinite  sequence  ( sn  |  n  £  tv)  over  X  such  that  for  every  n  £  tv, 

^(577+1 5  577+2)  7)  d(sn,  S77+1), 
and  sa,Sb  £  X  such  that  sa  7^  Sb  and  for  every  n  £  tv, 


d(sa,Sb)  7)  d(s„,  sn+i). 

34  For  every  set  A,  a  metric  function  on  A  is  a  function  d  from  A  X  A  to  1  such  that  for  any  a  \ .  a 2 ,  +3  £  A,  the  following 
are  true: 

1.  d(a  1,  02)  =  0  if  and  only  if  ai  =  02; 

2.  d(ai,  02)  =  d(a2,  ai); 

3.  d(a\,  a2)  +  d(a2,  a3)  >  d(ai,  a3). 

35  For  every  metric  space  (A,  d),  and  every  function  /  on  A,  f  is  a  contraction  mapping  on  [A,  d)  if  and  only  if  there  is 

c  E  [0, 1)  such  that  for  any  ai,  a2  E  A,  d(/(ai),  /(a2))  <  c  •  d(ai,  a2). 
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Assume  a  metric  function  d  on  A. 


Suppose,  toward  contradiction,  that  every  strictly  contracting  function  on  A  is  a  contraction  mapping  on 
(X,d). 

Assume  n  £  uj. 

Let  Fn  be  a  function  on  X  such  that  for  every  s  £  X, 

p  /  \  _  j  $a  if  d(s„,  s )  Z)  d(s„,  sn_(_i), 

"  |  Sb  otherwise. 


Then  Fn  is  strictly  contracting  (see  F\  in  proof  of  Theorem  A. 2).  Thus,  by  hypothesis,  Fn  is  a  contraction 
mapping  on  (X,  d),  and  hence,  there  is  cn  £  [0, 1)  such  that  for  every  s2  £  X, 

d(Fn(s'1),  Fn(s'2))  <  cn  ■  d(si,s'2). 


Thus, 


d(sa,Sf,)  —  di^Fn  (sn) ,  Fn  (sn+i ) ) 
£  Cn  *  d(sn,  Sn+l)* 


Thus,  for  every  n  £  uj, 


d(sa,Sf,)  <C  d(sn ,  ) . 


(39) 


Suppose  that  there  is  £  X  such  that 

{n  |  n  £  uj  and  d(sn+i,  s^)  d(sn,  sw)}  =  0. 

Let  F  be  a  function  on  X  such  that  for  every  s  £  X, 

_  /  ^min  {n\n  £  oj  and  d(sTl+i,s)73d(sTl,s)}  +  l  H  {fl  \  Tl  £  UJ  and  d(sn_|_i ,  s)  d(sn,  s)}  4^5 

I  Su  otherwise. 


Assume  s', ,  s'.2  £  X  such  that  .s'-,  4  s'2. 

Suppose  that 

{n  |  n  £  uj  and  d(sn+i,  si)  d(sn,si)}  4  0 

and 

{n  |  n  £  uj  and  d(sn+i,  s'2)  7$  d(sn,  s'2)}  4  0. 

Let  mi  =  min{n  |  n  £  uj  and  d(sn+i,  4)  7$  d(sI,,s,1)}. 
Let  m2  =  min{n  |  n  £  uj  and  d(s„+i,  s2)  d(sn,  s2)}- 
Then  F(s,1)  =  smi+1  and  F(s'2)  =  sm2+1. 

If  mi  =  m2 ,  then,  trivially, 

d(F(S'1),F(4))Dd(si,4). 
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Otherwise,  m\  ^  m 2.  Without  loss  of  generality,  assume  that  mi  <  m 2.  By  definition  of  mi 


d(smi_|_i,  Si)  7$  d(s  mi  5  ^l) ? 
and  since  (T,  2)  is  totally  ordered, 

d(smi,s'1)  2  d(s  rai+li  4)-  (40) 

Then,  by  the  generalized  ultrametric  inequality, 
d(smi ,  smi _)_i )  2  d(smi+i,  s-J, 

And  since  mi  <  m2,  by  Lemma  A. 31, 


d(smi,sm2)  2  d(sTOl+i,  sx).  (41) 

Suppose,  toward  contradiction,  that 

d(si,s'2)  3  d(smi ,  sm2).  (42) 

Then,  by  (41)  and  (42), 

d(4>4)  3  d(smi+i,si).  (43) 

Suppose,  toward  contradiction,  that 
d(smi+i,  s2)  Z)  d(s 

mi  +  li  4)-  (44) 


Then,  since  (T,  is  totally  ordered,  by  (43),  (44),  and  Proposition  2.7, 
d(smi+i,  si)  O  d(s  mt+li  sl)> 
obtaining  a  contradiction. 

Therefore, 

d(smi+i,  s2)  2  d(s  mi+l)  sl)j 
and  since  (T,  2)  is  totally  ordered, 

d(smi+i,  s:)  2  d(smi+i,  s2).  (45) 

Then,  by  (40),  (43),  (45),  and  the  generalized  ultrametric  inequality, 
d(smi,S2)  2  d(smi+i, s2). 

Thus,  mi  G  {n\n  G  uj  and  d(s„+i,  s2)  jb  d(s„,  s2)}>  and  since  mi  <  m2, 
min{n  |  n  G  uj  and  d(s„+i,s2)  2  d(sn,s2)}  <  m 2, 
obtaining  a  contradiction. 

Therefore, 

d(si,  s2)  yi  d(smi ,  sm2), 
and  since  (T,  2)  is  totally  ordered, 
d(smi ,  sm2)  2  d(si,  s2). 
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Then,  by  Lemma  A. 32, 


d(smi_|_i,  Sm2_|_i)  d(s^,S2), 

and  hence, 

d(F(S'1),F(4))Dd(si,4). 

Suppose  that  either 

{n  |  n  G  ui  and  d(sn+i,  s)  )  75  d(sn,si)}  ^  0 

and 

{n  |  n  G  w  and  d(sn+1,  s'2)  7$  d(s„,  s'2)}  =  0, 
or 

{n  |  n  G  w  and  d(sn+1,  si)  7$  d(sn,  si)}  =  0 

and 

{n  \  n  G  u>  and  d(sn+i,  s2)  7^  d(sn,  s^)}  7^  0. 

Without  loss  of  generality,  assume  that 

{n  |  n  G  ijJ  and  d(sn+i,  s'i)  7$  d(sn,si)}  7^  0 

and 

{n\n  G  oj  and  d(sn+1,  s'2)  7$  d(sn,  s'2)}  =  0, 

Let  mi  =  min  (n  |  n  €  oj  and  d(s„+i,  s})  7$  d(s„,s})}. 

Then  F(s,1)  =  smi+i  and  F(s'2)  =  su.  By  definition  of  mi, 

d(smi+i,s1)  yi  d(s 

mi  ?  ^l)  ? 

and  since  (T,  is  totally  ordered, 
d(smi ,  Sj^)  5  d(s 

mi  +  l)  si  )■  (46) 

Then,  by  the  generalized  ultrametric  inequality, 

d(smi,  smi+i)  3  d(smi+i,  sx).  (47) 

By  definition  of  sw, 

d('S77x1_|_i ,  s^;)  3  d(smi,sw),  (48) 

and  by  the  generalized  ultrametric  inequality, 

d(smi,  smi+i)  2  d(  $mi  1  S<jJ  )  • 


Suppose,  toward  contradiction,  that 

d(smi,  smi+i)  3  d(  5  So, )  • 
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(49) 


Then,  since  (T,  is  totally  ordered,  by  (48),  (49),  and  Proposition  2.7, 


d(smi5  su)  D  d(smi ,  s^), 


obtaining  a  contradiction. 
Therefore, 


and  hence,  by  (47), 

d(smi ,  su)  2  d(  s mi+l ;  sl)- 


(50) 


Suppose,  toward  contradiction,  that 
d(si,s2)  ^  d(smi ,  s^) . 


(51) 


Then,  by  (50)  and  (51), 

d(si,4)  3  d(smi+i,4)- 


(52) 


Suppose,  toward  contradiction,  that 
d(smi_|_i,  s2)  D  d(s  mi+l)  sl)- 


(53) 


Then,  since  (T,  is  totally  ordered,  by  (52),  (53),  and  Proposition  2.7, 


h(s?m  +  l ,  ^  d(s  rai  +  li  sl)> 


obtaining  a  contradiction. 
Therefore, 


d(smi+i,  s2)  d(smi+i,  sx), 


and  since  (T,  is  totally  ordered, 
d(smi+i,s1)  5  d(s  rai  +  li  s2)- 


(54) 


Then,  by  (46),  (52),  (54),  and  the  generalized  ultrametric  inequality, 


d(smi,s2)  5  d(smi+i,  s2). 


Thus,  mi  £  {n  \  n  £  oj  and  d(sn+i,  s2)  d(s„,  s2)}>  obtaining  a  contraction. 

Therefore, 

d(si,  s2)  7^  d(smi ,  Sqj) , 
and  since  (T,  ;<)  is  totally  ordered, 
d(smi,sw)  D  d(si,4)- 
Then,  by  (48), 

d(smi+i,  Su)  D  d(si,s2), 
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and  hence, 


d(F(s'),n4))3d(s'1,4). 

Otherwise, 

{n  |  n  G  w  and  d(sn+i,  si)  7$  d(sn,  si)}  =  0 

and 

{n  |  n  G  w  and  d(sn+i,  s'2)  7$  d(sn,  s'2)}  =  0, 

Then,  F(s})  =  sw  and  F(s2)  =  su,  and  thus,  trivially, 
d(F(si),F(s'2))Dd(si,s'2). 

Thus,  by  generalization,  F  is  strictly  contracting.  Thus,  by  hypothesis,  F  is  a  contraction  mapping  on 
( X ,  d),  and  hence,  there  is  c  G  [0, 1)  such  that  for  every  si ,  s'2  G  X, 

d{F(s‘ l),F(s'2))  <  c-  d(si,s'2). 

Assume  n  G  to. 

Trivially,  n  G  |?r'  |  n'  £  w  and  d(sn/+i,  sn)  7$  d(sn',  s„)},  and  thus, 

F{sn)  ^min  {n'\n'  £  U)  and  d(s^/  +  1,s„)  d(s^/,5n)}  +  l* 

Suppose,  toward  contradiction,  that  F(sn)  ^  sn+i.  Then  there  is  n!  G  w  such  that  n'  <  n  and 
d(sn'_j_i ,  Sn)  d(sn',  sn), 
and  since  (T,  ri)  is  totally  ordered, 
d(sn/,sn)  G)  d(sn/+i, s„). 

Then,  n!  +  1  <  n,  and  by  Lemma  A. 31, 
d(sn'_|_i,  sn)  —  d(sn/+i,  sn_(-i). 

Hence, 

d(sra/,  sn)  G)  d(sn/+i,  sn+i), 
in  contradiction  to  Lemma  A. 32. 

Therefore,  F{sn)  =  sn+i. 

Thus,  by  an  easy  induction,  for  every  n  G  w, 
d(F(sn),F(sn+ 1))  <  cn+1  ■  d(s0 ,  si), 
and  hence, 

d(sn,  sn_j_i)  GJ  c  •  d(s o,  Si). 

And  since  c  G  [0, 1),  by  (39)  and  (55), 
d(sa ,  Sfr)  —  0, 
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(55) 


obtaining  a  contradiction. 

Therefore,  there  is  a  strictly  contracting  function  on  X ,  namely  F,  that  is  not  a  contraction  mapping  on 
(X,d). 

Otherwise,  for  every  s  £  X, 

{n  |  n  £  u  and  d(sn+i,  su)  2$  d(sn,  sw)}  ^  0. 

Let  F  be  a  function  on  X  such  that  for  every  s  £  X, 

X(s')  -bum  { n\n  e  uj  and  d(5n+i,s)  ~jb  d(s„,s)}  +  l- 


Then,  by  the  same  argument,  F  is  strictly  contracting,  but  not  a  contraction  mapping  on  (X,d). 

Therefore,  there  is  a  strictly  contracting  function  on  X,  namely  F,  that  is  not  a  contraction  mapping  on 
(X,d).  "  '  □ 

Notice  that,  as  before,  it  is  still  possible  that  for  every  particular  strictly  contracting  function,  there  is 
some  metric  rendering  that  function  a  contraction  mapping.  But  a  unified  framework  facilitating  the 
representation  of  strictly  contracting  functions  as  contraction  mappings  is  impossible. 


64 


